I often hear the question from our customers, how data can be transformed prior to indexing in Splunk.
Damien from Baboonbones has done a tremendous job in creating add-ons providing custom inputs for Splunk. Most of his custom inputs provide the means to pre-process data by allowing custom event handlers to be written.
Sometimes you still want to pre-process data that gets collected from Splunk's standard input types, like file monitors, Windows EventLogs, scripted inputs etc. Also, not everyone is capable of writing custom event handlers.
A requirement these customers have, is that they have rolled out a large number of Splunk Universal Forwarders and they do not want to install another agent.
To summarize, the solution capable of pre-processing data, should be easy to use, be easily integrated and be build on top of their existing architecture.
How to plumb Splunk Pipelines
Splunk has its own fittings to connect a Universal Forwarder to a Heavy Forwarder o…