Getting Data In

identify the sender of an HEC data flow

gcusello
SplunkTrust
SplunkTrust

i at all,

I'm ingesting data using HEC in a distributed infratructure using a Load Balancer to distribute traffic from many senders between our Heavy Forwarders.

Now, I need to identify the sender of each event, is there a meta-data that identify the hostname and IP address of each sender?

I didn't find it in HEC documentation.

Thank you for your support.

Ciao.

Giuseppe

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
I’m afraid that there haven’t this kind of information unless your data didn’t contain it.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...