<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how can i add some description at all input log (metric, syslog, snmp, etc...) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/how-can-i-add-some-description-at-all-input-log-metric-syslog/m-p/568647#M100908</link>
    <description>&lt;P&gt;What do you mean by "description"? If you manipulate _meta, you touch fields _for every event_ of given sourcetype, source or host.&lt;/P&gt;&lt;P&gt;But if you do want to add a static field to your events (I do it on some of my forwarders to be able to quickly identify which forwarder the data came from) you should also add the field as indexed field in your fields.conf on search-heads&lt;/P&gt;</description>
    <pubDate>Tue, 28 Sep 2021 06:57:03 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-09-28T06:57:03Z</dc:date>
    <item>
      <title>how can i add some description at all input log (metric, syslog, snmp, etc...)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-can-i-add-some-description-at-all-input-log-metric-syslog/m-p/568638#M100907</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can i add some descriptions at all input log (metric, syslog, snmp, etc...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i tried, add "_meta = description::test_description" in UF inputs.conf&lt;/P&gt;&lt;P&gt;in this case, can be added description at all log&lt;/P&gt;&lt;P&gt;but, cant HF case&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... i think, what if it could be applied to heavy forwarder?&lt;/P&gt;&lt;P&gt;retried add "_meta ~~" in HF inputs.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but, not work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can i do?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 06:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-can-i-add-some-description-at-all-input-log-metric-syslog/m-p/568638#M100907</guid>
      <dc:creator>melonking</dc:creator>
      <dc:date>2021-10-13T06:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: how can i add some description at all input log (metric, syslog, snmp, etc...)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/how-can-i-add-some-description-at-all-input-log-metric-syslog/m-p/568647#M100908</link>
      <description>&lt;P&gt;What do you mean by "description"? If you manipulate _meta, you touch fields _for every event_ of given sourcetype, source or host.&lt;/P&gt;&lt;P&gt;But if you do want to add a static field to your events (I do it on some of my forwarders to be able to quickly identify which forwarder the data came from) you should also add the field as indexed field in your fields.conf on search-heads&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 06:57:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/how-can-i-add-some-description-at-all-input-log-metric-syslog/m-p/568647#M100908</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-09-28T06:57:03Z</dc:date>
    </item>
  </channel>
</rss>

