I want to take input from a forwarder, but before that, I want to filter the data with the help of a Python script.
Just like in a normal monitoring option, I used script to monitor a folder; like that, I want to monitor a folder on a box drive, but I want to use a script to pre-filter the data coming to Splunk.
You may filter the data using splunk props.conf & transforms.conf instead of scripts .
Reference : Route and filter data
If you still want to alter the data before pushing to splunk, one of the possible solution is