Getting Data In

Can phyton script modify a log event on the fly in a universal forwarder?

lpolo
Motivator

Can a phyton script modify a log event on the fly in a universal forwarder?

For example:

file.log:

timestamp <id=xxxx>{
json content
}

log event to be forwarded:

file.log:

{
"timestamp : "xx/xx/xx:xx:xx:xx",
"id" : "xxxx"
json content
}

Thanks for your guidance.

LP

Tags (1)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

This cannot be done at the Universal Forwarder. I'm not even sure it can be (simply) done at the indexer.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...