<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Append field to event data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Append-field-to-event-data/m-p/96882#M20208</link>
    <description>&lt;P&gt;hello,&lt;/P&gt;

&lt;P&gt;Using a custom script input I can obtain some data from a particular network resource. I would like to know if is possible to inject/append a field to the generated event indexed by splunk , so that I can augment my knowledge about each event.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 14 Oct 2013 14:47:57 GMT</pubDate>
    <dc:creator>rantravee</dc:creator>
    <dc:date>2013-10-14T14:47:57Z</dc:date>
    <item>
      <title>Append field to event data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Append-field-to-event-data/m-p/96882#M20208</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;

&lt;P&gt;Using a custom script input I can obtain some data from a particular network resource. I would like to know if is possible to inject/append a field to the generated event indexed by splunk , so that I can augment my knowledge about each event.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 14:47:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Append-field-to-event-data/m-p/96882#M20208</guid>
      <dc:creator>rantravee</dc:creator>
      <dc:date>2013-10-14T14:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Append field to event data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Append-field-to-event-data/m-p/96883#M20209</link>
      <description>&lt;P&gt;One approach would be to leverage lookups. Checkout:  &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources?r=searchtip"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Addfieldsfromexternaldatasources?r=searchtip&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;
You can create field=value pairs on the the fly to augment knowledge about your events.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 15:57:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Append-field-to-event-data/m-p/96883#M20209</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2013-10-14T15:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: Append field to event data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Append-field-to-event-data/m-p/96884#M20210</link>
      <description>&lt;P&gt;Interesting, but there seems to be a limitation.&lt;/P&gt;

&lt;P&gt;If I understood correctly, one can create new fields/values , but they must be somehow related to the event through an field that is already contained by the event.  &lt;/P&gt;

&lt;P&gt;I need to add/inject a field=value pair to my event , that is completely unrelated to any of it's fields.&lt;/P&gt;

&lt;P&gt;And I need to do it on the fly . Is there any possibility to allow me to do this&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2013 19:57:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Append-field-to-event-data/m-p/96884#M20210</guid>
      <dc:creator>rantravee</dc:creator>
      <dc:date>2013-10-14T19:57:03Z</dc:date>
    </item>
  </channel>
</rss>

