Good day Splunkers , We have a Data flow coming from the source A to Kakfa Topic. Splunk Connector on the kafka using HEC Token to forward data from the Kafka Topic to Splunk HF. Sourcetype if specified while configuring the HEC. This source event has huge volume , and have many key-value pairs , To Manage the High ingestion Volume , I need to apply truncate feature on all these events at the heavy forwarder layer before it reaches indexing layer. Is it possible to choose only selected fields from these events and have them indexed ? is it possible to use script applied on the source type to format the data which is coming from HEC input at the HF level ?
... View more