Getting Data In

[Forwarder] Data Filtering Issue

qkwltk
Path Finder

Hi,Guys And I'm splunk engineer.

Project progress, issues arose data that should be filtered through a splunk forwarder.
More information is shown below.

  1. light forwarder, universal forwarder in whether filtering
    : If it's not why should not on a specific technology

  2. Universal Forwarder to filter the data to be transferred through the Indexer settings

    : If it's not why should not on a specific technology

  3. Heavy Forwarder through data filtering, Forwarder installation Environment (actual commercial server) affect whether the resource
    : Occupied sure how much cpu, memory as compared to other forwarders(light, universal forwarder) ex. Content results in a specific environment of the POC ...etc

As a result, we want to get Offical Documents that Forwarder installed on the commercial server has not affected.

We have no time to do work , so I look forward to your answer assp!^^

Thanks!

Tags (1)
0 Karma

Ayn
Legend

Filtering can only be done on instances that perform parsing - in the forwarder case, only heavy forwarders do that.

Again, we can't do your work for you - if you have no time to do this, you should get someone who does.

0 Karma

Drainy
Champion

In your case, you might find paying for professional services to be useful

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...