Hello,
Please, in Splunk Enterprise, I would like to know if it is possible to apply an INGEST_EVAL processing at indexer layer for data that is coming to indexer from a HEC (http event collector).
Thanks
Hi
as transforms are handled on typing processor based on this picture https://www.aplura.com/assets/pdf/hec_pipelines.pdf it’s doable.
r. Ismo
Yep. +1 on that. HEC does skip some parts of the pipeline (line breaking, often timestamp recognition) but the index-time extractions and evals are applied normally.