This Add-On works together with the Owl Diode Sender Add-On (https://splunkbase.splunk.com/app/5554/). It is designed to send data between Splunk servers that can pass through a data diode, while preserving the Splunk metadata. The sender will encapsulate Splunk metadata like sourcetype, source, host, _time into the _raw message which can then be forwarded over syslog via UDP or TCP. The receiver will unpack this and populate the metadata fields as well and restore the _raw to its original state.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources