Hi, I need to filter out some events from a syslog source. The events are like this: Apr 28 14:15:09 10.130.4.203 Apr 28 14:15:09 hostname: User **** : Sign Off, ID: **, InstID: 4731, IPAddress: *****, FolderID: 0, Username: ******, AgentBrand: -, AgentVersion: -, XFerSize: 0, Error: 0 Apr 28 14:15:09 10.130.4.203 Apr 28 14:15:09 hostname: User **** : Upload, ID: **, InstID: 4731, IPAddress: *****, FolderID: 1234, Username: ******, AgentBrand: -, AgentVersion: -, XFerSize: 0, Error: 0 Apr 28 14:15:09 10.130.4.203 Apr 28 14:15:09 hostname: User **** : Sign Off, ID: **, InstID: 2819, IPAddress: *****, FolderID: 0, Username: ******, AgentBrand: -, AgentVersion: -, XFerSize: 0, Error: 0 I have two different InstID (4731 and 2819) and many FolderID, so I need to keep all the events with InstID:2189 and the events whith InstID:4731 and FolderID:0, so my goal is to discard by props.conf and transforms.conf all the events that have InstID:4731 and FolderID different from 0 Any help? Thanks in advance
... View more