\etc\system\local\transforms.conf
[drop4768OK]
REGEX = EventCode=4768(.|\t|\r|\n)*Result.*Code.*0x0
DEST_KEY = queue
FORMAT = nullQueue
\etc\system\local\props.conf
[source::WinEventLog:Security]
TRANSFORMS-set = drop4768OK
After a reboot, events with Event Code 4768 and Result Code 0x0 are still being indexed. What am I doing wrong?