A customer wants to mask unstructured data before sending it to Splunk Cloud. Where should SEBCMD be configured for this?
To mask unstructured data before sending it to Splunk Cloud, the SEDCMD should be configured in the props.conf file on a Heavy Forwarder. The Heavy Forwarder is responsible for data parsing and transformation before forwarding the data to Splunk Cloud. This ensures that sensitive data is masked before it reaches the indexing stage.
Splunk Documentation Reference: Using SEDCMD to Mask Data
Noemi
6 months agoLeonida
6 months agoFelicidad
6 months agoAvery
7 months agoGeoffrey
7 months agoDella
7 months agoIlene
7 months agoHayley
7 months agoMonte
8 months agoDavida
8 months agoMiriam
8 months agoNieves
8 months agoRonna
8 months agoJudy
2 years agoBrendan
1 year agoAlexia
1 year agoDaniel
1 year agoJesusita
1 year agoReuben
2 years agoPaz
2 years agoGabriele
1 year agoMargarita
1 year agoMatthew
2 years agoBo
2 years agoSharen
2 years agoAshton
2 years agoAntonio
2 years agoGlory
2 years agoParis
2 years agoKris
2 years agoBettina
2 years agoCristina
2 years agoPatti
2 years agoRomana
2 years agoVirgie
2 years ago