Being inspired by this sample I've developed my own modular input which loads data, parse it and after imports it to my Splunk Heavy Forwarder instance.
Now I plan to forward data from HF to a splunk instance (and maybe a 3rd party splunk instance), but I'd like to process it before forwarding it - there is any way to preprocess forwarded data?
I consider the parsing your modular input does to be "preprocessing". What additional processing do you want to do?
my target is add alert upon forwarded messages.
Kind of - if forwarded event's field type is 5, the forwarding module should call an REST API and additionally forward the event to a second receiver....