Can the universal forwarder monitor event logs and filter out events using REGEX in whitelist
for eg:
[WinEventLog://MyLog]
........
.......
whitelist= SourceName="^MySource$"
? If so which version onward can the universal forwarder achieve this functionality?
Universal Forwarders can use regexes in the inputs.conf whitelist settings, that's dating back very far if not all the way until the first versions of UFs... certainly 4.3, 5, and 6.
As for inter-version compatibility, you can use 6.x UFs with 5.x indexers and vice versa.
http://docs.splunk.com/Documentation/Splunk/6.1.4/Forwarding/Compatibilitybetweenforwardersandindexe...