When I try use :
transforms.conf
[setnull] REGEX = 192\.168\.1\.50, 172\.16\.1\.50 DEST_KEY = queue FORMAT = nullQueue
props.conf
[cisco] TRANSFORMS-null = setnull
In event I get all result. But when I use only one ip its woks good. If any way for exclude more than one ip.
Hi @elvis5,
it's a regex, you have to use pipe ("|") as OR condition, not comma separated values:
[setnull]
REGEX = (192\.168\.1\.50)|(172\.16\.1\.50)
DEST_KEY = queue
FORMAT = nullQueue
props.conf
Ciao.
Giuseppe
Thanks it works!
Hi @elvis5,
if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉