This message originated from Cribl Community Slack.
Click here to view the original link.
Is they any way to capture a full Splunk HEC payload coming into the Splunk HEC source before it breaks out the event into _raw? I have a source sending into /services/collector/event so I know event in the JSON is what gets stored as _raw. I would like to see the rest of the JSON outside of the event field when the data is sent. It is a cloud based source so I cannot check on that end. Is this possible?
Sign up
Already have an account? Login
Login to the community
No account yet? Create an account
Using your Cribl Curious or University Account
User Login Employee loginEnter your E-mail address. We'll send you an e-mail with instructions to reset your password.
