This is done by defining a regex to match the necessary event(s) and send everything else to
Here is a basic example that will drop everything except events that contain the string
This example only includes things that contain 'login' and drops everthing else. Another use case would be to take in everything and make an exception for nosie you want filtered out.
The inverse to accept all except anything with the word 'info' would require just one stanza in transforms.conf:
answered 08 Apr '10, 19:56
See this post:
This is done by defining a regex to match the necessary event(s) and send everything else to nullqueue
Here is a basic example that will drop everything except events that contain the string login
answered 29 Apr '10, 22:56
I ran into the same pitfall but I don't know any way out of it. I need to discard certain noisy syslog events and keep the rest.
I also tried :
I use the Cisco Security Suite App, thus the syslog port moved to 2000 for coexistence with the standard syslog service.
Do you have an idea for further troubleshooting?
answered 07 Dec '11, 07:14