sean_auditum, I have had the same issue. I wanted to redirect WinEventLog:Setup and XmlWinEventLog:Security to a different index as the logs were/are coming in main index. I have had a similar stanza as yours except I had "REGEX = ." in transforms.conf to send all logs to a different index. However, WinEventLog:Setup working but XmlWinEventLog:Security is not. Still investigating. I'll provide an update once I resolve this issue.
... View more