diff --git a/Vagrant/resources/splunk_server/transforms.conf b/Vagrant/resources/splunk_server/transforms.conf index 66fb9bb..0f9b468 100644 --- a/Vagrant/resources/splunk_server/transforms.conf +++ b/Vagrant/resources/splunk_server/transforms.conf @@ -14,8 +14,8 @@ DEST_KEY = MetaData:Host REGEX = hostIdentifier\"\:\"([^\"]+)\" FORMAT = host::$1 -[setnull] -REGEX = Error\scasting +[osquery_status_filter] +REGEX = (POST\srequest\sto\sURI|Refreshing\sconfiguration|not\sattaching|Executing\sscheduled\squery|Error\scasting) DEST_KEY = queue FORMAT = nullQueue