A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?
To mask unstructured data before sending it to Splunk Cloud, the SEDCMD should be configured in the props.conf file on a Heavy Forwarder. The Heavy Forwarder is responsible for data parsing and transformation before forwarding the data to Splunk Cloud. This ensures that sensitive data is masked before it reaches the indexing stage.
Splunk Documentation Reference: Using SEDCMD to Mask Data
Judy
1 months agoJesusita
2 days agoReuben
1 months agoPaz
1 months agoGabriele
5 days agoMargarita
23 days agoMatthew
26 days agoBo
1 months agoSharen
2 months agoAshton
2 months agoAntonio
26 days agoGlory
1 months agoParis
1 months agoKris
2 months agoBettina
1 months agoCristina
1 months agoPatti
2 months agoRomana
2 months agoVirgie
2 months ago