<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add host name in event ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17902#M2397</link>
    <description>&lt;P&gt;if the answer suits you, you can accept it.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Nov 2012 15:18:44 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2012-11-05T15:18:44Z</dc:date>
    <item>
      <title>How to add host name in event ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17898#M2393</link>
      <description>&lt;P&gt;I am forwarding data from indexer to heavy forwarder  How I can append host name in event (_raw) in indxer that will be forwarded to heavy forwarder ? &lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 04:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17898#M2393</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2012-10-31T04:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to add host name in event ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17899#M2394</link>
      <description>&lt;P&gt;Can you explain why you are doing this ? What is the heavy forwarder sending to ?&lt;/P&gt;

&lt;P&gt;If you want to export data, use a scheduled search to export search results formated as you   wish &lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 06:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17899#M2394</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-10-31T06:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to add host name in event ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17900#M2395</link>
      <description>&lt;P&gt;The actual scenario is like this: I am sending data like this...&lt;/P&gt;

&lt;P&gt;universalforwarder -&amp;gt; indexer -&amp;gt; Heavy forwarder -&amp;gt; Syslog-ng server&lt;/P&gt;

&lt;P&gt;How Can I get Universal forwarder machine address in Syslog-ng server.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2012 14:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17900#M2395</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2012-11-01T14:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to add host name in event ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17901#M2396</link>
      <description>&lt;P&gt;Here is the method to add any metadata (like host) in the events.&lt;BR /&gt;
Do that at the indexer level (during index time)&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/40848/how-can-i-rewriteadd-info-from-metadata-to-the-contents-of-the-raw-log-line"&gt;http://splunk-base.splunk.com/answers/40848/how-can-i-rewriteadd-info-from-metadata-to-the-contents-of-the-raw-log-line&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2012 14:51:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17901#M2396</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-11-01T14:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to add host name in event ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17902#M2397</link>
      <description>&lt;P&gt;if the answer suits you, you can accept it.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 15:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-host-name-in-event/m-p/17902#M2397</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-11-05T15:18:44Z</dc:date>
    </item>
  </channel>
</rss>

