We're working with a 30 day trial as we wait for procurement to purchase a full license. While learning and configuring the system, I'm working on getting rid of some events we don't want to see. So far it's not working. My first question is, will this work on a Trial license? If it will, here's what my files looks like. I've tried as many combinations and formats as I can find examples for. I had the Transforms settings all in one stanza to start with, below is my latest attempt. If I run "splunk btool check", I see no errors. Help! Please . props.conf: [WinEventLog:Security] TRANSFORMS-security = setnull0 [WMI:WinEventLog:System] TRANSFORMS-wmisystem = setnull1 [WinEventLog:System] TRANSFORMS-system = setnull2 transforms.conf: [setnull0] SOURCE_KEY = dest REGEX = ^EventCode=(1107|4688|7036|10028)\D DEST_KEY = queue FORMAT = nullQueue [setnull1] SOURCE_KEY = dest REGEX = ^EventCode=(1107|4688|7036|10028)\D DEST_KEY = queue FORMAT = nullQueue [setnull2] SOURCE_KEY = dest REGEX = ^EventCode=(1107|4688|7036|10028)\D DEST_KEY = queue FORMAT = nullQueue
... View more