<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding host attributes (fields?) at index time in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Adding-host-attributes-fields-at-index-time/m-p/164036#M46596</link>
    <description>&lt;P&gt;Can this be done in a configuration file on the host itself? I'd like to configure all of this through Ansible in our splunk role. Similar to the inputs.conf.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2015 17:24:20 GMT</pubDate>
    <dc:creator>kbutlerhc1</dc:creator>
    <dc:date>2015-03-04T17:24:20Z</dc:date>
    <item>
      <title>Adding host attributes (fields?) at index time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-host-attributes-fields-at-index-time/m-p/164034#M46594</link>
      <description>&lt;P&gt;New to splunk, so bear with me. &lt;/P&gt;

&lt;P&gt;As I'm setting it up in our environment, we are forwarding logs from multiple "environments" (think prod, qa, stage, etc). What I would like to do is at the host level, define what environment it comes from so that searches are easily filterable. env="prod" for example&lt;/P&gt;

&lt;P&gt;According to this article, it seems "not recommended" to do what I want to do. &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configureindex-timefieldextraction"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Data/Configureindex-timefieldextraction&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Am I looking in the right place? What's the proper way to do this? &lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2015 16:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-host-attributes-fields-at-index-time/m-p/164034#M46594</guid>
      <dc:creator>kbutlerhc1</dc:creator>
      <dc:date>2015-03-04T16:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Adding host attributes (fields?) at index time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-host-attributes-fields-at-index-time/m-p/164035#M46595</link>
      <description>&lt;P&gt;The proper way to do this is by using tags&lt;/P&gt;

&lt;P&gt;And set up them accordingly, for example&lt;/P&gt;

&lt;P&gt;host=dev1   tag -&amp;gt; DEV&lt;/P&gt;

&lt;P&gt;This way you can change it any time, as this is appliedon search time&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2015 16:34:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-host-attributes-fields-at-index-time/m-p/164035#M46595</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2015-03-04T16:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Adding host attributes (fields?) at index time</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-host-attributes-fields-at-index-time/m-p/164036#M46596</link>
      <description>&lt;P&gt;Can this be done in a configuration file on the host itself? I'd like to configure all of this through Ansible in our splunk role. Similar to the inputs.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2015 17:24:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-host-attributes-fields-at-index-time/m-p/164036#M46596</guid>
      <dc:creator>kbutlerhc1</dc:creator>
      <dc:date>2015-03-04T17:24:20Z</dc:date>
    </item>
  </channel>
</rss>

