Getting Data In

Getting metadata such as host, source, and source type when sendCookedData is set to false ?

dk30390
New Member

Actually I need all the event changes from Splunk forwarders(Universal and Heavy both) into a third party system, so I am using a java socket connection to get all the event changes in raw form, for that, I have added sendCookedData = false in outputs.conf configuration file under $SPLUNK_HOME/etc/system/local/. But as a downside of this change, I am not getting any metadata such as host, source, and source type, etc.
But I need these metadata in my application. Is there any way to get these metadata when we are forwarding the event changes to a third party system in raw form?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...