Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

How to configure a heavy forwarder to filter out the ending string from Windows security event logs?

$
0
0
Hello guys I'm trying to drop the end of all Security events: This event is generated when a logon session is created. It is generated on the computer that was accessed. .... My conf files on Heavy Forwarder is: transforms.conf [win-event-cut-en] DEST_KEY = _raw REGEX = ((.*+[\v])+)(?=This event is generated when) FORMAT = $1 props.conf [WinEventLog:Security] TRANSFORMS-windows_events =win-event-cut-en However, this does not work.

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>