Hi
We need to ingest only those events which starts with any of the below strings ; (please note its starts with not contains)
create, drop, login, logout, alter, delete
For example
“ login success for user Peter”
"create action success for user Martin"
we have edited the transforms.conf as below
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[setparsing]
REGEX = login|logout!|create|drop|alter|DELETE
DEST_KEY = queue
FORMAT = indexQueue
But this is allowing all events which contains above strings. But our requirement is event should start with above strings;
Could you please help us with a PCRE regex for above conditions on transforms.conf?
Hi @roopeshetty ,
the symbol for starting log is "^", so you should try this:
REGEX = ^login|logout!|create|drop|alter|DELETE
or
REGEX = ^(login|logout!|create|drop|alter|DELETE)
probably the second is the orrect one.
Ciao.
Giuseppe