Search code examples
jsonsplunkraw-data

Splunk HEC: Start sending events in JSON format with pre existing raw events


We are using Splunk Enterprise v 6.6.3. All our indexed events are raw events (logs) and we are planning to use Splunk HEC and send the events in JSON format.

My question: does sending the new events in JSON format affect everything that we have today in Splunk?


Solution

  • Once events are indexed in Splunk they cannot change. Nothing you do with new events will affect anything already in Splunk.