Getting Data In

How to force to set certain fields (host and sourcetype) for events from HEC local stanza for each token

gots
Path Finder

Is it possible to force Splunk to set up specific fields (sourcetype, source, host) from HEC local stanza
but not from event parameters?

For example if i have inputs.conf like:

[http://http_test]
description = test hec input
disabled = 0
connection_host = dns
index = main
source = test_hec_source
sourcetype = test_hec_sourcetype

Client can rewrite index, host, source and sourcetype if post in data json like:

{
  "host": fake_host,
  "sourcetype": fake_sourcetype,
  "index": fake_index,
  "source": fake_source
}

But in certain situations i need to deny modifications of this parameters. Of course i can do it with transforms.conf, but it is not convinient.

mdsnmss
SplunkTrust
SplunkTrust

You should be able to override source and define sourcetype for HEC during configuration I know for sure. I don't believe you can for host. You should also be able to override fields using props and transforms at the indexers.

props.conf

[<original sourcetype>]
TRANSFORMS-force_host = force_host
TRANSFORMS-force_source = force_source
TRANSFORMS-force_sourcetype=force_sourcetype

transforms.conf

[force_host]
DEST_KEY=MetaData:Host
FORMAT = <your_host>

[force_source]
DEST_KEY=MetaData:Source
FORMAT = <your_source>

[force_sourcetype]
DEST_KEY=MetaData:Sourcetype
FORMAT = <your_sourcetype>

The only thing I am unsure of is Splunk's order of operations. If it changes the sourcetype first, would it no longer see that sourcetype for the event and skip the host and source override? I would have to test but, if so, you should be able to just create a new stanza for the new sourcetype.

https://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Data/Advancedsourcetypeoverrides

0 Karma

gots
Path Finder

you are right about HEC configuration if sourcetype, host and over fields are not defined in event.
But if sender define this fields, he will override valued defined in inputs.conf.

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

In HEC configs, source/sourcetype settings come under the "per-token" settings: http://dev.splunk.com/view/event-collector/SP-CAAAE6Q.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...