splunk uf internal logs are picked up by a passthru pipeline in cribl. based on index.startsWith('_') for the route filter. That works fine.
the problem, i lose all meta information about the splunk ufs. like version and os. Can this be prevented somehow?
I just see all the cribl workers and some machines (HF) that are sending data directly to splunk
Original post was from https://cribl-community.slack.com/archives/CPYBPK65V/p1693930511929089
Solved
Access Splunk UF meta data
Best answer by Jon Rust
internal fields can be accessed in pipelines like any other, but to view them you need to do as Tony shows above
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.


