Merge pull request #456 from clong/osquery_status_filter
Filter noisy osquery status info messages from Splunk
This commit is contained in:
@@ -21,7 +21,7 @@ TIME_FORMAT = %s
|
|||||||
TRUNCATE = 0
|
TRUNCATE = 0
|
||||||
|
|
||||||
[osquery:status]
|
[osquery:status]
|
||||||
TRANSFORMS-null = setnull
|
TRANSFORMS-null = osquery_status_filter
|
||||||
|
|
||||||
[WinEventLog]
|
[WinEventLog]
|
||||||
TRANSFORMS-null = autoruns_wineventlog_null
|
TRANSFORMS-null = autoruns_wineventlog_null
|
||||||
|
|||||||
@@ -14,8 +14,8 @@ DEST_KEY = MetaData:Host
|
|||||||
REGEX = hostIdentifier\"\:\"([^\"]+)\"
|
REGEX = hostIdentifier\"\:\"([^\"]+)\"
|
||||||
FORMAT = host::$1
|
FORMAT = host::$1
|
||||||
|
|
||||||
[setnull]
|
[osquery_status_filter]
|
||||||
REGEX = Error\scasting
|
REGEX = (POST\srequest\sto\sURI|Refreshing\sconfiguration|not\sattaching|Executing\sscheduled\squery|Error\scasting)
|
||||||
DEST_KEY = queue
|
DEST_KEY = queue
|
||||||
FORMAT = nullQueue
|
FORMAT = nullQueue
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user