Deployment Architecture

Splunk integration with third party systems

asp12
New Member

Hi All,

To forward data to third-party systems, integrated  splunk agent with below configs. 

Third party is able to receive data by listening on TCP port.

Issue: Unable to view default internal fields like source or host required for data enrichment. 

              Tried adding host and source in inputs.conf, but no luck.

Is there any limitation for forwarding internal fields to third party systems?

inputs.conf

[blacklist:$SPLUNK_HOME/var/log/splunk]

[monitor:///tmp/test1.log]

_TCP_ROUTING = App1Group

 

outputs.conf

[tcpout:App1Group]

server=<ip address>:<port>

sendCookedData = false

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...

Avoid Certificate Expiry Issues in Splunk Enterprise with Certificate Assist

This blog post is part 2 of 4 of a series on Splunk Assist. Click the links below to see the other ...