we have one HF , configured to routing into 3 destinations
2 * syslogNG
1* Splunk HF cluster
our requirement is to drop the specific eventcode 33205 from windows logs , to the one syslogNG destination .. but the same eventcode, need to be recieved by another syslogNG and splunk HF cluster .
when I try to configure, it drop the eventcode for all destinations if i use below entries
Props.conf
[source::WinEventLog:Application]
TRANSFORMS-routing = drop_sqld
Transforms.conf
[drop_sqld]
REGEX = (?i)EventCode=33205
DEST_KEY = _raw
FORMAT = nullQueue
can you help on this possiblity ?
You need to manipulate the _SYSLOG_ROUTING key, not queue (and definitely not _raw!)
okay thanks, but we have 2 syslog destinations in this intermediate HF ..both syslogNG's destination key configured as _syslog_routing
Need to block the specific windows event code in one syslogNG and need to forward that eventcode in another syslogNG ..
for both syslogNG destinations , configured in different output group in outputs.conf