Update transforms.conf
This commit is contained in:
@@ -23,3 +23,15 @@ FORMAT = nullQueue
|
|||||||
REGEX = "Script\sName\s=\sC\:\\Program Files\\AutorunsToWinEventLog\\AutorunsToWinEventLog.ps1"
|
REGEX = "Script\sName\s=\sC\:\\Program Files\\AutorunsToWinEventLog\\AutorunsToWinEventLog.ps1"
|
||||||
DEST_KEY = queue
|
DEST_KEY = queue
|
||||||
FORMAT = nullQueue
|
FORMAT = nullQueue
|
||||||
|
|
||||||
|
[removeEventDesc1]
|
||||||
|
LOOKAHEAD = 20000
|
||||||
|
REGEX = (?msi)(.*)This event is generated
|
||||||
|
DEST_KEY = _raw
|
||||||
|
FORMAT = $1
|
||||||
|
|
||||||
|
[removeEventDesc2]
|
||||||
|
LOOKAHEAD = 20000
|
||||||
|
REGEX = (?msi)(.*)The subject fields indicate
|
||||||
|
DEST_KEY = _raw
|
||||||
|
FORMAT = $1
|
||||||
|
|||||||
Reference in New Issue
Block a user