<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic can I pass additional source info from inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86985#M18053</link>
    <description>&lt;P&gt;Is it possible to pass extra info from inputs.conf?&lt;/P&gt;

&lt;P&gt;e.g. [inputs.conf]&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = my_host&lt;/P&gt;

&lt;P&gt;[monitor://somepath]&lt;BR /&gt;
sourcetype = my_source&lt;BR /&gt;
additional_info = my_additional_info&lt;/P&gt;

&lt;P&gt;I want this additional info from all the forwarder, due to some reason I can not use host name.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 14:16:37 GMT</pubDate>
    <dc:creator>jangid</dc:creator>
    <dc:date>2020-09-28T14:16:37Z</dc:date>
    <item>
      <title>can I pass additional source info from inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86985#M18053</link>
      <description>&lt;P&gt;Is it possible to pass extra info from inputs.conf?&lt;/P&gt;

&lt;P&gt;e.g. [inputs.conf]&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = my_host&lt;/P&gt;

&lt;P&gt;[monitor://somepath]&lt;BR /&gt;
sourcetype = my_source&lt;BR /&gt;
additional_info = my_additional_info&lt;/P&gt;

&lt;P&gt;I want this additional info from all the forwarder, due to some reason I can not use host name.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:16:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86985#M18053</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2020-09-28T14:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: can I pass additional source info from inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86986#M18054</link>
      <description>&lt;P&gt;From the splunk documentation there is no additional parameters can be passed. But what is the difference between the sourcetype and additional_info? it's the same if we use in search.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2013 10:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86986#M18054</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2013-07-08T10:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: can I pass additional source info from inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86987#M18055</link>
      <description>&lt;P&gt;this is my custom information. I want to add this information along with sourcetype and is should be searchable. similar to sourcetype, source and host.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2013 10:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86987#M18055</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2013-07-08T10:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: can I pass additional source info from inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86988#M18056</link>
      <description>&lt;P&gt;You need to set custom fields. Reference below URL.&lt;BR /&gt;
But this is not recommended by Splunk.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/Configureindex-timefieldextraction"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/Configureindex-timefieldextraction&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Generally you should use custom fields at search time, editing props.conf or transforms.conf.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsatsearchtime"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsatsearchtime&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2013 11:23:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/can-I-pass-additional-source-info-from-inputs-conf/m-p/86988#M18056</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-07-08T11:23:26Z</dc:date>
    </item>
  </channel>
</rss>

