Getting Data In

Using Data Preview on data received by forwarders

danielpellarini
Path Finder

I have a forwarder sending some log files to an indexer. I have configured the inputs.conf file on the forwarder to create a new sourcetype from these logs. The forwarder correctly sends the data with the correct sourcetype but I need to adjust how linebreaking behaves.

I know I could modify props.conf on the forwarder to solve this, but in this case I would like to do it through Data Preview. However, so far I have only found a way to use this feature with data residing on the server and not from files coming from forwarders. Is it possible to use Data Preview on data coming from a forwarder?

martin_mueller
SplunkTrust
SplunkTrust

I don't think so.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...