diff --git a/Vagrant/resources/splunk_server/props.conf b/Vagrant/resources/splunk_server/props.conf index bc6dcab..d4bd90d 100644 --- a/Vagrant/resources/splunk_server/props.conf +++ b/Vagrant/resources/splunk_server/props.conf @@ -21,7 +21,7 @@ TIME_FORMAT = %s TRUNCATE = 0 [osquery:status] -TRANSFORMS-null = setnull +TRANSFORMS-null = osquery_status_filter [WinEventLog] -TRANSFORMS-null = autoruns_wineventlog_null \ No newline at end of file +TRANSFORMS-null = autoruns_wineventlog_null diff --git a/Vagrant/resources/splunk_server/transforms.conf b/Vagrant/resources/splunk_server/transforms.conf index 66fb9bb..0f9b468 100644 --- a/Vagrant/resources/splunk_server/transforms.conf +++ b/Vagrant/resources/splunk_server/transforms.conf @@ -14,8 +14,8 @@ DEST_KEY = MetaData:Host REGEX = hostIdentifier\"\:\"([^\"]+)\" FORMAT = host::$1 -[setnull] -REGEX = Error\scasting +[osquery_status_filter] +REGEX = (POST\srequest\sto\sURI|Refreshing\sconfiguration|not\sattaching|Executing\sscheduled\squery|Error\scasting) DEST_KEY = queue FORMAT = nullQueue