I have a quick and probabyly simple question, I needed to ignore an event for arguments sake lets call it event 123
So I created a transforms.conf and added the below -
REGEX = 123
DEST_KEY = queue
FORMAT = nullQueue
After restarting the Splunk service this has had the desired effect in that eventcode 123 is no longer being indexed, it stops appearing on the search at the same time that I restarted the service. To my question / confusion, in doing this it seems that the event 123 is actually also no longer being shown in the Windows event log.
1 is this correct, will the stanza that I have added stop the events being logged in the windows event viewer
2 should it not still be logged in the windows event viewer and just ignored when indexing all the other events ?
or is this just a complete coincidence and the event 123 has just resolved itself at the exact same time as I was working on ignoring that particular event.