<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk forwarder to add custom fields for multiple logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200939#M187572</link>
    <description>&lt;P&gt;Where are you writing the JVM logs to on the host?  What's the full path?&lt;/P&gt;

&lt;P&gt;You can use &lt;STRONG&gt;host_regex&lt;/STRONG&gt; or &lt;STRONG&gt;host_segment&lt;/STRONG&gt; to extract the JVM "hostname" out of the log file path.  Splunk would then replace the built-in host field with that value.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.2/admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.2/admin/Inputsconf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2016 18:46:30 GMT</pubDate>
    <dc:creator>jchampagne_splu</dc:creator>
    <dc:date>2016-01-07T18:46:30Z</dc:date>
    <item>
      <title>Splunk forwarder to add custom fields for multiple logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200936#M187569</link>
      <description>&lt;P&gt;I have to setup Splunk for 100 servers, each server will have 5-10 JVMs, Each JVM generates 3-4 log files. I would like to index logs to a central Splunk server and along with data , I would also like to send custom fields. so that I can uniquely search JVM logs or different files. for example a NullPinterException in JVM= "ABC" and in log file Server.log or in jms.log.&lt;BR /&gt;
How can I design the deployment and custom fields?&lt;/P&gt;

&lt;P&gt;The deployment looks like the following &lt;BR /&gt;
Server A-&amp;gt;&lt;BR /&gt;
    JVM 1-&amp;gt;&lt;BR /&gt;
          server.log&lt;BR /&gt;
          jakarta.log&lt;BR /&gt;
          httpd.log&lt;BR /&gt;
          jms.log&lt;BR /&gt;
     JVM 2-&amp;gt;&lt;BR /&gt;
          server.log&lt;BR /&gt;
          jakarta.log&lt;BR /&gt;
          httpd.log&lt;BR /&gt;
         jms.log&lt;/P&gt;

&lt;P&gt;Server B-&amp;gt;&lt;BR /&gt;
    JVM 3-&amp;gt;&lt;BR /&gt;
          server.log&lt;BR /&gt;
          jakarta.log&lt;BR /&gt;
          httpd.log&lt;BR /&gt;
          jms.log&lt;BR /&gt;
     JVM 4-&amp;gt;&lt;BR /&gt;
          server.log&lt;BR /&gt;
          jakarta.log&lt;BR /&gt;
          httpd.log&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 11:15:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200936#M187569</guid>
      <dc:creator>z001k6jr</dc:creator>
      <dc:date>2015-12-24T11:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder to add custom fields for multiple logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200937#M187570</link>
      <description>&lt;P&gt;Just a question, have you run through the spunk tutorial? &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.2/SearchTutorial/WelcometotheSearchTutorial"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.2/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also I recommend you give this a read first as well: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.2/Indexer/Howindexingworks"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.2/Indexer/Howindexingworks&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;People will definitely give you a hand but having some familiarity with the basics will make it easier of you to get the answers you need&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 21:24:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200937#M187570</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2015-12-24T21:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder to add custom fields for multiple logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200938#M187571</link>
      <description>&lt;P&gt;How can I design the deployment and custom fields?&lt;/P&gt;

&lt;P&gt;Sorry, but I'm not going to build the solution for you.  I recommend you delete this question and only ask specific questions like... I get this error "complete error message" , how can I fix it?  Not, I just got a new job as splunk admin and need to know how to setup deployment server and develop applications.  The answer to your questions are covered in documentation, best practices, and splunk training sessions.  All of which are available to you.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2015 15:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200938#M187571</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2015-12-28T15:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder to add custom fields for multiple logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200939#M187572</link>
      <description>&lt;P&gt;Where are you writing the JVM logs to on the host?  What's the full path?&lt;/P&gt;

&lt;P&gt;You can use &lt;STRONG&gt;host_regex&lt;/STRONG&gt; or &lt;STRONG&gt;host_segment&lt;/STRONG&gt; to extract the JVM "hostname" out of the log file path.  Splunk would then replace the built-in host field with that value.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.2/admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.2/admin/Inputsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 18:46:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-forwarder-to-add-custom-fields-for-multiple-logs/m-p/200939#M187572</guid>
      <dc:creator>jchampagne_splu</dc:creator>
      <dc:date>2016-01-07T18:46:30Z</dc:date>
    </item>
  </channel>
</rss>

