I am trying to create an event breaker to add to a HEC source. Can you use __hecToken as a filter condition for the breaker or does the breaker happen before that internal field gets added?
I dont need this breaker to apply to all the data coming into this HEC source
see diagram here for the order: https://docs.cribl.io/stream/event-processing-order#
short answer: breaker comes before the metadata fields
ok so i can use _raw.includes ?
or _raw.indexOf ?
In my experience i was able to use __hecToken as filter condition