Both of the above regex searches aren't filtering anything out. Here's a sample event.  
       endpoint="https://xxx.service-now.com/",business_duration="1970-01-01 00:00:00",start_time="2017-11-21 09:21:32",duration="1970-01-01 00:00:00",sys_updated_on="2017-11-21 09:21:33",has_breached="false",sys_created_on="2017-11-21 09:21:33",sys_id="d6f9a8s7d6f9a78sd6f9a78sd6f9a78s",sys_tags="",end_time="",pause_time="",task="sd9f8g6s9df8g69sd8f7g6sdfgs9df87",planned_end_time="2017-11-28 09:21:32",active="true",pause_duration="",sla="xyz",original_breach_time="2017-11-28 09:21:32",percentage="0",sys_mod_count="0",sys_updated_by="asdf",business_time_left="1970-01-03 02:00:00",stage="in_progress",timezone="Europe/London",schedule="asd9f8asd9f78as6d9f876sd9f786asd",business_percentage="0",time_left="1970-01-08 00:00:00",business_pause_duration="",sys_created_by="asdf"
    host = splunk source = https://xxx.service-now.com/ sourcetype = snow:task_sla
  
 Here's a btool snippet of my transforms.conf: 
  [setnull]
CAN_OPTIMIZE = True
CLEAN_KEYS = True
DEFAULT_VALUE = 
DEST_KEY = queue
FORMAT = nullQueue
KEEP_EMPTY_VALS = False
LOOKAHEAD = 4096
MV_ADD = False
REGEX = .
SOURCE_KEY = _raw
WRITE_META = False
[setparsing]
    CAN_OPTIMIZE = True
    CLEAN_KEYS = True
    DEFAULT_VALUE = 
    DEST_KEY = queue
    FORMAT = indexQueue
    KEEP_EMPTY_VALS = False
    LOOKAHEAD = 4096
    MV_ADD = False
    REGEX = sla\=\"abc\"
    SOURCE_KEY = _raw
    WRITE_META = False
  
 Btool snippet of props.conf: 
  [snow:task_sla]
ANNOTATE_PUNCT = True
AUTO_KV_JSON = true
BREAK_ONLY_BEFORE = 
BREAK_ONLY_BEFORE_DATE = True
CHARSET = AUTO
DATETIME_CONFIG = \etc\datetime.xml
FIELDALIAS-snow:task_sla:tak_sys_id = task AS task_sys_id
HEADER_MODE = 
LEARN_SOURCETYPE = true
LINE_BREAKER_LOOKBEHIND = 100
LOOKUP-sla_supplier_lookup = sla_supplier_lookup sys_id AS sla OUTPUTNEW name AS sla_definition priority sla_supplier
MAX_DAYS_AGO = 2000
MAX_DAYS_HENCE = 2
MAX_DIFF_SECS_AGO = 3600
MAX_DIFF_SECS_HENCE = 604800
MAX_EVENTS = 256
MAX_TIMESTAMP_LOOKAHEAD = 128
MUST_BREAK_AFTER = 
MUST_NOT_BREAK_AFTER = 
MUST_NOT_BREAK_BEFORE = 
SEGMENTATION = indexing
SEGMENTATION-all = full
SEGMENTATION-inner = inner
SEGMENTATION-outer = outer
SEGMENTATION-raw = none
SEGMENTATION-standard = standard
SHOULD_LINEMERGE = True
TRANSFORMS = 
TRANSFORMS-set = setnull,setparsing
TRUNCATE = 10000
detect_trailing_nulls = auto
maxDist = 100
priority = 
sourcetype = 
  
						
					
					... View more