A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?
To mask unstructured data before sending it to Splunk Cloud, the SEDCMD should be configured in the props.conf file on a Heavy Forwarder. The Heavy Forwarder is responsible for data parsing and transformation before forwarding the data to Splunk Cloud. This ensures that sensitive data is masked before it reaches the indexing stage.
Splunk Documentation Reference: Using SEDCMD to Mask Data
Judy
20 days agoReuben
24 days agoPaz
29 days agoMargarita
7 days agoMatthew
10 days agoBo
16 days agoSharen
1 months agoAshton
1 months agoAntonio
10 days agoGlory
24 days agoParis
26 days agoKris
2 months agoBettina
21 days agoCristina
23 days agoPatti
1 months agoRomana
2 months agoVirgie
2 months ago