Getting Data In

How to filter out or send to a null queue windows event logs with universal forwarder 6.x?


i'm using UF6 and I want to filter out or send to a null queue uninteresting Windows events with UF6.

0 Karma


we can filetr the unwanted traffic to be dropped by moving them to nullQueue.

TRANSFORMS-debug_log = debug_log_transform

in transforms.conf:
DEST_KEY = queue
FORMAT = nullQueue

so the respective matched REGEX data will not be indexed and therefore it will not affect our license limit too.

0 Karma


Besides routing to receivers, forwarders can also filter and route data to specific queues or discard the data altogether by routing to the null queue.

0 Karma


this only works on an indexer not on an UF as stated in the question

0 Karma


Hi liquid,

take a look at the docs Use_the_Security_event_log_to_monitor_changes_to_files this will provide examples on how to blacklist certain windows event log entries by event code.

also good to read:

hope this helps ...

cheers, MuS