Are those really joined on one line? If so, then you have no active configurations. It should be like this:
# Filtrage de tout sauf les accept
TRANSFORMS-remove_juniper_permit = remove_juniper_permit
# Accepter tout sauf les Permit
REGEX = action=Permit
DEST_KEY = queue
FORMAT = nullQueue
But the real problem is that this needs to be deployed to your Indexers (not forwarder) and all Splunk instances there need to be restarted. Then check the newly forwarded/indexed events (old Permits will still be there). This all assumes that the events have sourcetype of JuniperFW.