<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add custom tags to event data via universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305137#M57527</link>
    <description>&lt;P&gt;Tags are applied at searchtime, so the easist way to do this is to built event types for each of your scenarious and then attach a tag to an event type. &lt;/P&gt;

&lt;P&gt;There is a great splunk video here: &lt;A href="http://www.splunk.com/view/SP-CAAAGYJ"&gt;http://www.splunk.com/view/SP-CAAAGYJ&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2017 18:46:20 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2017-02-15T18:46:20Z</dc:date>
    <item>
      <title>How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305136#M57526</link>
      <description>&lt;P&gt;I am using universal forwarder.&lt;/P&gt;

&lt;P&gt;I wish to tag my logs with the application and some custom information like groupA or groupB etc. So, I wish to have multiple tags to my events namely applog1, groupA. &lt;/P&gt;

&lt;P&gt;I understand we can do it from _meta in inputs.conf. But, that does not seem to work. In fact, once I add a tag, none of the events are shown in search.&lt;/P&gt;

&lt;P&gt;Is there any other way to do that ? Any pointers will help. &lt;/P&gt;

&lt;P&gt;Thanks and Regards,&lt;BR /&gt;
Abhay Dandekar&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 17:53:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305136#M57526</guid>
      <dc:creator>dandekarabhay</dc:creator>
      <dc:date>2017-02-15T17:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305137#M57527</link>
      <description>&lt;P&gt;Tags are applied at searchtime, so the easist way to do this is to built event types for each of your scenarious and then attach a tag to an event type. &lt;/P&gt;

&lt;P&gt;There is a great splunk video here: &lt;A href="http://www.splunk.com/view/SP-CAAAGYJ"&gt;http://www.splunk.com/view/SP-CAAAGYJ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 18:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305137#M57527</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-02-15T18:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305138#M57528</link>
      <description>&lt;P&gt;Thanks, the video was great.&lt;BR /&gt;
But, is there any automated way to add institutional data to Splunk ? I was looking at forwarders for those, but somehow they are not working for adding tags to the existing fields.&lt;/P&gt;

&lt;P&gt;Thanks and Regards,&lt;BR /&gt;
Abhay Dandekar&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 15:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305138#M57528</guid>
      <dc:creator>dandekarabhay</dc:creator>
      <dc:date>2017-02-20T15:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305139#M57529</link>
      <description>&lt;P&gt;You can do it at the app level at &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.2/Admin/Tagsconf"&gt;tags.conf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can create one tag from the UI (so you see when it ends up) and then add more to this &lt;CODE&gt;tags.conf&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 15:33:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305139#M57529</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-20T15:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305140#M57530</link>
      <description>&lt;P&gt;This video is excellent - one of my favorites ; -) &lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 15:34:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305140#M57530</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-02-20T15:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305141#M57531</link>
      <description>&lt;P&gt;what do you mean "institutional data"?&lt;/P&gt;

&lt;P&gt;If you mean common sourcetypes like syslog, windows events, LDAP, network events, firewall logs, ids logs, antivirus logs, proxy logs ... etc, etc.. then,  take a look at &lt;A href="http://apps.splunk.com/"&gt;splunkbase&lt;/A&gt; where you will find apps for all sorts of data. These applications commonly include automatic extractions and tags to identify and classify those datatypes automatically and apply them to a common information model.&lt;/P&gt;

&lt;P&gt;If you mean something which is a little more bespoke to your organisation, you may need to perform some of the extractions and apply tags yourself. &lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 17:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305141#M57531</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-02-20T17:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305142#M57532</link>
      <description>&lt;P&gt;Thanks for a quick response. &lt;/P&gt;

&lt;P&gt;By institutional data, I mean data that cannot be derived directly and needs to be provided by user.&lt;/P&gt;

&lt;P&gt;I am planning to add such information as tags at forwarding level itself.&lt;/P&gt;

&lt;P&gt;Does that provide enough information ?&lt;/P&gt;

&lt;P&gt;Thanks and Regards,&lt;BR /&gt;
Abhay Dandekar&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 17:23:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305142#M57532</guid>
      <dc:creator>dandekarabhay</dc:creator>
      <dc:date>2017-02-20T17:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305143#M57533</link>
      <description>&lt;P&gt;Splunk principally (but is not limited) to collecting data from log files. It in these cases one would normally deploy a universal forwarder to read the logs from the target system and then provide the content back to the Splunk indexer. - This assumes your data is in log files of some type.&lt;/P&gt;

&lt;P&gt;If your data is to be collected from an API, TCP socket or a scripted process you have built you will probably want to consider a heavy forwarder which has the capabilities of the UF as well the means to run shell scripts or hooks via python.&lt;/P&gt;

&lt;P&gt;I must admit that from your description I am not clear on your use case, but "tagging" has a specific meaning in the context of Splunk. I hope I am not doing you a disservice by suggesting you are referring to something else &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I don't know if you are able to provide some sample data or maybe describe your use case in detail?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2017 18:40:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/305143#M57533</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-02-20T18:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to add custom tags to event data via universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/509612#M86680</link>
      <description>&lt;P&gt;Is&amp;nbsp;tags.conf&amp;nbsp; a config that can be applied at the config of universal-forwarder or is it an indexer config only feature?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Where would it have to be place in the forwarder directory to make it effective?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have tried:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/tags.conf&lt;BR /&gt;&lt;BR /&gt;with the following config:&lt;BR /&gt;&lt;BR /&gt;[host=myhost.mydomain.net]&lt;BR /&gt;nonproduction=enabled&lt;BR /&gt;testsystem=enabled&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 21:21:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-custom-tags-to-event-data-via-universal-forwarder/m-p/509612#M86680</guid>
      <dc:creator>tomaszez</dc:creator>
      <dc:date>2020-07-16T21:21:23Z</dc:date>
    </item>
  </channel>
</rss>

