Getting Data In

identify the sender of an HEC data flow

gcusello
SplunkTrust
SplunkTrust

i at all,

I'm ingesting data using HEC in a distributed infratructure using a Load Balancer to distribute traffic from many senders between our Heavy Forwarders.

Now, I need to identify the sender of each event, is there a meta-data that identify the hostname and IP address of each sender?

I didn't find it in HEC documentation.

Thank you for your support.

Ciao.

Giuseppe

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
I’m afraid that there haven’t this kind of information unless your data didn’t contain it.
0 Karma
Get Updates on the Splunk Community!

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...