Getting Data In
Highlighted

TRANSFORMS-ROUTING filtering out source address

Contributor

I have set up a TRANSFORMS-ROUTING and it is forwarding data to a 3rd party however, they do not want to see the source address the logs are coming from. Is there a quick way i can remove the source IP form the data being sent over?

the logs look like this-
timestamp 10.10.10.10 logs message blahhh foo blahhh foooooooo blahhh

props-
[host::hostA*]
TRANSFORMS-ROUTING = sendtoparty

transforms -
[sendtoparty]
REGEX = .
DESTKEY = _SYSLOGROUTING
FORMAT = sendtopartygroup1

outputs-
[syslog:sendtopartygroup1]
server = 10.22.22.22:514
type = udp
syslogSourceType = sourcetype::none

0 Karma
Highlighted

Re: TRANSFORMS-ROUTING filtering out source address

Champion

You can try using SEDCMD in props.conf. Refer below documents:
http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/Propsconf

0 Karma
Highlighted

Re: TRANSFORMS-ROUTING filtering out source address

Contributor

i should have said we are doing this on a HWF so this wont work because SEDCMD will only work at index time.. right?

0 Karma