Skip to main content
Question

Is there any workaround to send uncooked data from Splunk HF to Cribl?

  • March 11, 2025
  • 8 replies
  • 75 views

Perry Correll

Hey,Is there any workaround to send uncooked data from Splunk HF to Cribl? (dest::Splunktcp)The issue is that the EB(Cribl) is not taking any effect (I'd read before it will be skipped by design limitations).tried to set sendCookedData = false but the data flow had stopped eventually, then added negotiateProtocolLevel = 0 but it didn't help, other trial was to use dest::tcp source but ingestion has stopped as well. Any ideas how we can overcome this scenario.

8 replies

Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

Cribl can totally process data that has already been processed by a HF before


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

The other way wouldn't work (without ugly hacks)


Perry Correll
  • Author
  • Employee
  • March 11, 2025

Then how can it re-process them although it skips the EB in Cribl source


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

Oh, that's supposed to mean event breaker


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

So, what issue do you have? Are your events improperly broken on the HF, and how?


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

Is one event containing multiple events? That could be fixed. Is one event only containing parts of one event? That's something that can't really be fixed later


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

Yeah, that's something you need to fix on the HF (or bypass it ")


Perry Correll
  • Author
  • Employee
  • March 11, 2025

The latter unfortunately, thats why I'm not using the event breaker function in the pipeline