Getting Data In

INGEST_EVAL for data coming from HEC at indexer layer

cafissimo
Communicator

Hello, 

Please, in Splunk Enterprise, I would like to know if it is possible to apply an INGEST_EVAL processing at indexer layer for data that is coming to indexer  from a HEC (http event collector).

Thanks

Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as transforms are handled on typing processor based on this picture https://www.aplura.com/assets/pdf/hec_pipelines.pdf it’s doable.

r. Ismo

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yep. +1 on that. HEC does skip some parts of the pipeline (line breaking, often timestamp recognition) but the index-time extractions and evals are applied normally.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...