I am trying to remove the extra description text that gets appended to windows 2k8 logs using SEDCMD in props.conf. However, I can't seem to get it to work, no matter what i use as my expression. I am receiving events from a light forwarder on a windows box that is pulling the events using WMI from our domain controllers. The indexer is actually a linux box.
This is what I have in props.conf
Nothing is being removed. I've tried all kinds of variations on both the stanza name as well as the regular expression itself. I've tried just [WMI:WinEventLog:Security], [WMI:WinEventLog*], [WMI*], and even the name of one of the hosts: [host::<hostname>]
I've also tried different variations of the regex. Even something like this doesn't do any replacement:
I've tried with and without (single or double) quotes around the entire part after the = as well. Thoughts?
The problem is that the
You'd actually a stanza to match against sourcetype
answered 03 Feb '11, 20:58