Dashboards & Visualizations

It is possible to "tag" all data coming into a particular HEC token?

twinspop
Influencer

I have about 50 different tokens. I want data from one particular token to get some metadata added to it. Unfortunately, it doesn't appear that the _meta directive works for http in inputs.conf. Is it possible to replicate this functionality some how?

0 Karma

MuS
SplunkTrust
SplunkTrust

The inputs name will translate into a source::http:InputNameHere which in turn should be useable in props.conf
But I must admit, I have not yet tried it 😉

cheers, MuS

twinspop
Influencer

Well shoot. If the sending application sets source, that overrides the default above, which means the transform doesn't fire. So still back to the old problem: How to guarantee a transform gets applied to every single event that came through a particular token's input def?

0 Karma

MuS
SplunkTrust
SplunkTrust

In this case, did someone say cough cribl cough 😉

twinspop
Influencer

We're testing it, but not ready to roll into production. Yet. 🙂 Very promising!

0 Karma

twinspop
Influencer

Perfect! I had no idea that was a thing. I feel like I gained a new superpower.

0 Karma

MuS
SplunkTrust
SplunkTrust

Glad I could help - Enjoy the new superpower 🙂

cheers, MuS

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi twinspop,

you can always use the good old props.conf / transforms.conf approach and add a meta field this way. Here is an example transforms.conf I use to add the hostname of the parsing HWF to events:

[add-relay-info-to-meta]
FORMAT = splunk_hwf::HostNameHere
REGEX = .
WRITE_META = true

Yes, it is a static value but I assume you will not change your HEC input too often 😉

Hope this helps ...

cheers, MuS

0 Karma

twinspop
Influencer

Yeah, a transform is where i was headed, but I don't see any foolproof way to identify only those those logs, and ALL those logs, that originate on 1 particular token. The token value and the input name are not things I can key off of in props as far as i know.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...