<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to know what inputs.conf a given event came from? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-know-what-inputs-conf-a-given-event-came-from/m-p/122494#M25358</link>
    <description>&lt;P&gt;The beauty and curse of the conf file is that they all stack.&lt;BR /&gt;
if you found the correct source, but have several inputs matching it, the best solution is run a btool and check how they merge.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk cmd btool inputs list --debug&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2014 19:14:09 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2014-04-07T19:14:09Z</dc:date>
    <item>
      <title>How to know what inputs.conf a given event came from?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-know-what-inputs-conf-a-given-event-came-from/m-p/122493#M25357</link>
      <description>&lt;P&gt;So if you have any reasonably complicated deployment, likely you have a fair number of inputs.conf that your UF is reading. &lt;/P&gt;

&lt;P&gt;If you are trying to change a field on given event that is being forwarded... like say a log that needs a different sourcetype... and you want to change that stanza from the appropriate input.conf how do you know which one to change? Is the only way to do a search of the content of the file? Trounle is, it is not always clear what stanza and in which file caused an event to be forwarded.&lt;/P&gt;

&lt;P&gt;Much like "source" which tells you exactly what file the data came from, I was thinking about adding a "conf" field to show exactly which inputs.conf had forwarded on this particular event.&lt;/P&gt;

&lt;P&gt;So how is this sort of thing tracked in a large scale environment according to best practices?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 19:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-know-what-inputs-conf-a-given-event-came-from/m-p/122493#M25357</guid>
      <dc:creator>neiljpeterson</dc:creator>
      <dc:date>2014-04-07T19:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to know what inputs.conf a given event came from?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-know-what-inputs-conf-a-given-event-came-from/m-p/122494#M25358</link>
      <description>&lt;P&gt;The beauty and curse of the conf file is that they all stack.&lt;BR /&gt;
if you found the correct source, but have several inputs matching it, the best solution is run a btool and check how they merge.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk cmd btool inputs list --debug&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2014 19:14:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-know-what-inputs-conf-a-given-event-came-from/m-p/122494#M25358</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2014-04-07T19:14:09Z</dc:date>
    </item>
  </channel>
</rss>

