A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?
To mask unstructured data before sending it to Splunk Cloud, the SEDCMD should be configured in the props.conf file on a Heavy Forwarder. The Heavy Forwarder is responsible for data parsing and transformation before forwarding the data to Splunk Cloud. This ensures that sensitive data is masked before it reaches the indexing stage.
Splunk Documentation Reference: Using SEDCMD to Mask Data
Reuben
16 hours agoPaz
6 days agoSharen
11 days agoAshton
13 days agoGlory
19 hours agoParis
3 days agoKris
29 days agoPatti
16 days agoRomana
1 months agoVirgie
1 months ago