<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to trace or tag events to know which specific Heavy Forwarder the events have passed through? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274824#M52720</link>
    <description>&lt;P&gt;Hi kearaspoor,&lt;/P&gt;

&lt;P&gt;You can always use &lt;CODE&gt;props.conf&lt;/CODE&gt; and &lt;CODE&gt;transforms.conf&lt;/CODE&gt; on each of the HWF to add or change any data going through this HWF. Take a look at this answer &lt;A href="https://answers.splunk.com/answers/40848/how-can-i-rewrite-add-info-from-metadata-to-the-contents-of-the-raw-log-line.html"&gt;https://answers.splunk.com/answers/40848/how-can-i-rewrite-add-info-from-metadata-to-the-contents-of-the-raw-log-line.html&lt;/A&gt; which provides a solution to add a &lt;CODE&gt;host&lt;/CODE&gt; and &lt;CODE&gt;source&lt;/CODE&gt; into the &lt;CODE&gt;_raw&lt;/CODE&gt; data. &lt;/P&gt;

&lt;P&gt;Be advised that this will increase license usage and also could produce other complications - this is only to show you that it is possible &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Mon, 12 Sep 2016 20:44:59 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2016-09-12T20:44:59Z</dc:date>
    <item>
      <title>How to trace or tag events to know which specific Heavy Forwarder the events have passed through?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274822#M52718</link>
      <description>&lt;P&gt;We've got more than a dozen Heavy Forwarders (HF) that are behind a pair of load balancers that handle all our system log (syslog) traffic.  Is there any way to trace back or tag the events to know which specific HF they were passed through?   &lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 19:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274822#M52718</guid>
      <dc:creator>kearaspoor</dc:creator>
      <dc:date>2016-09-12T19:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to trace or tag events to know which specific Heavy Forwarder the events have passed through?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274823#M52719</link>
      <description>&lt;P&gt;On prem or cloud? Source IP and port against your firewall logs if it is the latter. Are all the events indexed in single file?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 20:13:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274823#M52719</guid>
      <dc:creator>jrbanks6</dc:creator>
      <dc:date>2016-09-12T20:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to trace or tag events to know which specific Heavy Forwarder the events have passed through?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274824#M52720</link>
      <description>&lt;P&gt;Hi kearaspoor,&lt;/P&gt;

&lt;P&gt;You can always use &lt;CODE&gt;props.conf&lt;/CODE&gt; and &lt;CODE&gt;transforms.conf&lt;/CODE&gt; on each of the HWF to add or change any data going through this HWF. Take a look at this answer &lt;A href="https://answers.splunk.com/answers/40848/how-can-i-rewrite-add-info-from-metadata-to-the-contents-of-the-raw-log-line.html"&gt;https://answers.splunk.com/answers/40848/how-can-i-rewrite-add-info-from-metadata-to-the-contents-of-the-raw-log-line.html&lt;/A&gt; which provides a solution to add a &lt;CODE&gt;host&lt;/CODE&gt; and &lt;CODE&gt;source&lt;/CODE&gt; into the &lt;CODE&gt;_raw&lt;/CODE&gt; data. &lt;/P&gt;

&lt;P&gt;Be advised that this will increase license usage and also could produce other complications - this is only to show you that it is possible &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2016 20:44:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274824#M52720</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2016-09-12T20:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to trace or tag events to know which specific Heavy Forwarder the events have passed through?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274825#M52721</link>
      <description>&lt;P&gt;It's a range of devices including routers, switches, firewall, various security and networking appliances so they're ending up in a half-dozen or so individual indexes.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 14:13:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274825#M52721</guid>
      <dc:creator>kearaspoor</dc:creator>
      <dc:date>2016-09-13T14:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to trace or tag events to know which specific Heavy Forwarder the events have passed through?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274826#M52722</link>
      <description>&lt;P&gt;Thanks for the suggestion.  We're currently bumping our license limit so thank you for the warning about that particular complication.&lt;/P&gt;

&lt;P&gt;I'll also have to ponder this a bit because I want to keep the existing host/source information I just want to add the heavy forwarder as a troubleshooting/monitoring function.   Not to mention the complications of managing separate props/transforms on each heavy forwarder.. I hadn't previously considered that added complexity.  But you've given me a good place to start.  Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2016 14:20:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-trace-or-tag-events-to-know-which-specific-Heavy/m-p/274826#M52722</guid>
      <dc:creator>kearaspoor</dc:creator>
      <dc:date>2016-09-13T14:20:50Z</dc:date>
    </item>
  </channel>
</rss>

