Getting Data In

identify the sender of an HEC data flow

gcusello
SplunkTrust
SplunkTrust

i at all,

I'm ingesting data using HEC in a distributed infratructure using a Load Balancer to distribute traffic from many senders between our Heavy Forwarders.

Now, I need to identify the sender of each event, is there a meta-data that identify the hostname and IP address of each sender?

I didn't find it in HEC documentation.

Thank you for your support.

Ciao.

Giuseppe

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
I’m afraid that there haven’t this kind of information unless your data didn’t contain it.
0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...