I need to reduce our licensing usage by filtering common, valid, no-news-is-good-news domains out of our Barracuda Web Filter logs. I am trying to do this by sending such log messages to the nullQueue, but I clearly am not doing it correctly.
The set_bwf transform works, but the bwf_discard transform does not.
Given that I am a regex newbie, I suspect that I have crafted the regular expression under "[bwf_discard]" incorrectly.
It looks like your regex should work, you don't need the (?m) for multi-line matching, and I would suggest making the regex slight more specific to the host field (rather than matching anywhere in the event), but that shouldn't stop it from working.
You can try this, but I suspect your issue is elsewhere.