I have over 300 Universal forwarders and I'm getting several eventcode=5156 events errors. Is there a way to blacklist this event on a heavy forwarder? If not, what would be the best approach for blacklisting this event code?
the best way is to insert the blacklisted value in your TA distributed to all the Universal Forwarders
blacklist = EventCode\=5156
Otherwise you could filter these events in your Heavy Forwarder:
[set_nullqueue] REGEX=EventCode\=5156 DEST_KEY=queue FORMAT=nullQueue [set_OK] REGEX=. DEST_KEY = queue FORMAT = indexQueue
Thanks Giuseppe for your response. I tried to do it on the heavy fwd but it did not work. Please see below to see what i inserted in the props.conf and transforms.conf file.
[set_nullqueue] REGEX=EventCode=5156 DEST_KEY=queue FORMAT=nullQueue [set_OK] REGEX=. DEST_KEY = queue FORMAT = indexQueue
please disregard, it did work. Thanks for your help.
Glad you found a working solution through @cusello. Please don't forget to resolve the post by clicking "Accept" directly below his answer, and upvote his answer for helping you out.