When you create forward filter to forwarder list of event id’s to SPLUNK, you can say Account Name choose don’t forward anything that ends with $ this will not forward for all event ID’s, but if you want to forward anything that ends with $ for one or two event id in your list. How do you create the filter so it will forwarder everything including anything that ends with $ for that specific event id? I don’t see option in InTrust 11.4.