We are sending logs to a third party system.
And in the inputs.conf monitor stanza, we have set:
sendCookedData = false sourcetype = errorlogs index = logs_index
sendCookedData = false because we are forwarding logs to a third party system.. (Mentioned in doc)
Also, we have set the sourcetype and specified an index..
Can we read the sourcetype set for the data at the receiving end?
For now we are able to see only the plain loglines.
Appreciate any help!
Hey thanks for your answer. But cooked data looks like its encoded on the receiving side. Is there a way to decode / retrieve sourcetype from cooked data in a third party receiver ?
Cooked data is a Splunk proprietary format, for Splunk to Splunk communication.
If you are sending to a 3rd party, I dont understand why you need an index our sourcetype, these are Specific to Splunk. What are you trying to integrate the feed with? Have you checked this: