1.My universal forwarder sending Binary data to Heavy Forwarder in Index name as "Binary_index" .
2.On heavy Forwarder I want to convert these Binary data to csv format,for which I have written python script and then send CSV data to splunk instance.
But I don't know I to achieve this
please provide me solution with configuration files details for every steps.
It would be great help if you provide detailed solution for this,since I am new to splunk .
please provide the configuration files details for reading binary data on universal forwarder side.
There are two things: (for the below approach there is no need to python script)
1. First you can locally index the data and send it to some other server as well. Check the below link:
2. Now after data is indexed, you can schedule a report in Splunk where you can outputlookup search results in csv.