Getting Data In

Redirecting data through two heavy forwarders, is it possible to reprocess already cooked data with props.conf and transforms.conf?

daniel333
Builder

All,

I have data flowing through a heavy forwarder. Security wants a SECOND heavy forwarder that they manage to SEDCMD out certain PII. Is it possible to reprocess already cooked data?

0 Karma

lukejadamec
Super Champion

No. Once the data is passed the parsing phase it cannot go back. Even worse, you could end up with a situation where the events from a search show the SEDCMD data, but the interesting fields and _raw show the original data.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...