Add some Splunk nullQueues for noisy events
This commit is contained in:
@@ -21,4 +21,8 @@ TIME_FORMAT = %s
|
||||
TRUNCATE = 0
|
||||
|
||||
[osquery:status]
|
||||
TRANSFORMS-null = setnull
|
||||
TRANSFORMS-null = setnull
|
||||
|
||||
[WinEventLog]
|
||||
TRANSFORMS-null = osqueryd_wineventlog_null
|
||||
TRANSFORMS-null = autoruns_wineventlog_null
|
||||
Reference in New Issue
Block a user