Hello,
I have some trouble sending out system metrics from an Edge node to eventually Splunk. When the data stream is leaving Edge (captured at step 4) it still contains internal fields related to a metric event. When the data is collected in Stream all of those internal fields are missing and I'm ending up with a _raw field. There are no pipelines interfering with the data at all between Edge and Stream. Just a passthrough is set. Am I missing the point here?
Do I have to manually transform the _raw to metric events again from Stream forwards? Is there a way to preserve the internal fields from Edge to Stream? Last resort is to send it out directly to Splunk HEC from Edge node but I want to channel as much through Stream as possible.
Any thoughts? Thanks in advance!,
Reemster