Is it possible to send Splunk HEC events message part to 3rd party collector/arcsight?
Eg... Now it is :
Logstash --- SplunkHEC/ HF --- Indexer
I want to parse message field in the HEC and send to arcsight collector before being send to indexers.
Is it possible?
Kindly help.