We should stop asking folks to filter out at the Indexer when a capability exists at UF. Why have the Indexer incur regex hits and use network bandwidth for nothing (sending over pipe to Indexer that is going to drop on the floor) when a noisy Windows EventID can be filtered at the source?
... View more