TRANSFORMS-ReadData_bktfileserver = filter_ReadData
TRANSFORMS-filter4663 = filter_4663_readdata
REGEX = EventCode=4663.*?ReadData (or ListDirectory)
DEST_KEY = queue
FORMAT = nullQueue
I'm not quite sure I understood your question.
What do you mean by "filter"? Extracting the field or discarding it?
At the moment, you are creating the field "filter4663" in props.conf and tie it to your regex in transforms.conf, which gets discarded by FORMAT=nullQueue. So eventcode 4663 is replaced with nothing.
The regex doesn't seem to be valid, it should look like this:
REGEX = (?i)EventCode=4663.*ReadData\s\(or\sListDirectory\)
thanks for the answer,
the point is that i want to drop all eventcodes 4663 for Object access with message "ReadData", because i have too much logs. BUT 4663 is for DELETE either. thats why i want to filter based on message attached to eventcode.