Please assume the below in transforms.conf

FORMAT = indexer1

REGEX = CEF\:0\|ids
FORMAT = nothing

REGEX = CEF\:0\|ids
FORMAT = syslog_group

The objective here is to send all event to the tcp out unless they match the regex CEF:0|ids in which case events should be sent to the syslog out.

What I can't sort out is how to reset the _TCP_ROUTING back to nothing in those events that are routed to syslog (since I don't want to have them duplicated).

Anyone has any idea here ?

Thanks !

(More details can be found here :

