All Apps and Add-ons

Assign hosts a category/group automatically

springworks
Engager

Hi!

I have just installed the unix app on some hosts and it seems to be report data as it should.

My issue now is how I group my different hosts in an automatic way. I have a VPC in Amazon Web Services with quite a lot of instances that I want to group by. Many of them are in auto-scaling groups which means new instances can be started at any time.

What I'm looking for is a way to specify on each host what group or category they belong. Maybe set in a config file or with a splunk command, doesn't matter.

Appreciate any help!

Thanks

araitz
Splunk Employee
Splunk Employee

Per http://docs.splunk.com/Documentation/UnixApp/latest/User/First-timeconfiguration#Settings:_Categorie...

Use the Settings: Categories page to
add host categories and groups. When
you make these changes, the Splunk App
for Unix and Linux writes them to
$SPLUNK_HOME/etc/apps/SA-nix/lookups/dropdowns.csv.

As such, you can just have your script populate this file directly, maintaining the same column names, column order, etc.

0 Karma

springworks
Engager

I already have information on every host to group them by, like hostname. But if that wont suffice, I want to add some tag or something similar in a config that will result in hosts assigning to the correct groups automatically. Not sure if those links you provided @somesoni2 will do that..? Thanks

0 Karma

somesoni2
Revered Legend

I believe you may utilize splunk event type/tags for the same, provided you have some common element to group the hosts (name patterns etc).

http://docs.splunk.com/Documentation/Splunk/6.1/Knowledge/defineeventtypes
http://docs.splunk.com/Documentation/Splunk/6.1/Knowledge/TagandaliasfieldvaluesinSplunkWeb

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...