Can we apply following example on UF?
https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Keep_specific_eve...
The answer is no. The example is for any non-UF instance.
For UF you can modify the example
[source::/var/log/messages] TRANSFORMS-set= setnull,setparsing
[setnull] REGEX = . DEST_KEY = queue FORMAT = nullQueue [setparsing] REGEX = \[sshd\] DEST_KEY = _TCP_ROUTING FORMAT = <valid-tcpoutgroup(s)>
Or
[source::/var/log/messages] TRANSFORMS-set= setnull,setparsing
[setnull] REGEX = . DEST_KEY = queue FORMAT = nullQueue [setparsing] REGEX = \[sshd\] DEST_KEY = queue FORMAT = parsingQueue