Getting Data In

How to add prefix string to events before forwarding to external server?

Zanusha443
Explorer

Hi everybody,

I would like to duplicate data coming from my sourcetype in such a way:

- send the original data to Splunk for indexing.

- send the duplicated events to an external server with "<DNS>" prefix string.

How should I modify the transform.conf file in order to do that?

Another question: is there a better way to forwards logs to external server while keeping the original source  host (source IP) instead of adding prefixes like what I'm trying to do. 

Thanks in advance,

Angelo

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...