Archive
Highlighted

LWF send source name when raw

Splunk Employee
Splunk Employee

Is there a way to make Light Forwarder include the name of the file it is sending events from (i.e. source) when sending raw data to a 3rd party system?

Tags (1)
0 Karma
Highlighted

Re: LWF send source name when raw

Splunk Employee
Splunk Employee

i believe LWF does that by default, for example, when you see in the indexer you can tell what the source is, this was brought by the LWF.

Hence i am assuming you need to train the third party system to recognize this field from the raw data..

0 Karma
Highlighted

Re: LWF send source name when raw

Splunk Employee
Splunk Employee

Unfortunatly outputs.conf has 'sendCookedData = false'. And we are senting to a 3rd party system. So the data stream only has the raw event.

0 Karma
Highlighted

Re: LWF send source name when raw

Splunk Employee
Splunk Employee

The data stream is raw to 3rd party. No source, sourcetype or Host.

0 Karma