Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Send data to different index if Packet Broker tags events

$
0
0
Hi, i have a setup where a packet broker is sending multiple data streams to a universal forwarder. I need to understand if the traffic is tagged somehow from a particular source (replay a pcap file through packet broker), can I use inputs.conf with the tagged 'field' that will hopefully show a difference so i can send to a specific index or do i need to use props / transforms / outputs? thanks in advance Damindra

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>