Getting Data In

[Forwarder] Data Filtering Issue

qkwltk
Path Finder

Hi,Guys And I'm splunk engineer.

Project progress, issues arose data that should be filtered through a splunk forwarder.
More information is shown below.

  1. light forwarder, universal forwarder in whether filtering
    : If it's not why should not on a specific technology

  2. Universal Forwarder to filter the data to be transferred through the Indexer settings

    : If it's not why should not on a specific technology

  3. Heavy Forwarder through data filtering, Forwarder installation Environment (actual commercial server) affect whether the resource
    : Occupied sure how much cpu, memory as compared to other forwarders(light, universal forwarder) ex. Content results in a specific environment of the POC ...etc

As a result, we want to get Offical Documents that Forwarder installed on the commercial server has not affected.

We have no time to do work , so I look forward to your answer assp!^^

Thanks!

Tags (1)
0 Karma

Ayn
Legend

Filtering can only be done on instances that perform parsing - in the forwarder case, only heavy forwarders do that.

Again, we can't do your work for you - if you have no time to do this, you should get someone who does.

0 Karma

Drainy
Champion

In your case, you might find paying for professional services to be useful

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...