Getting Data In

Redirecting data through two heavy forwarders, is it possible to reprocess already cooked data with props.conf and transforms.conf?



I have data flowing through a heavy forwarder. Security wants a SECOND heavy forwarder that they manage to SEDCMD out certain PII. Is it possible to reprocess already cooked data?

0 Karma

Super Champion

No. Once the data is passed the parsing phase it cannot go back. Even worse, you could end up with a situation where the events from a search show the SEDCMD data, but the interesting fields and _raw show the original data.

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!