Getting Data In

How to add host name in event ?

kml_uvce
Builder

I am forwarding data from indexer to heavy forwarder How I can append host name in event (_raw) in indxer that will be forwarded to heavy forwarder ?

kamal singh bisht
Tags (1)
0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

Can you explain why you are doing this ? What is the heavy forwarder sending to ?

If you want to export data, use a scheduled search to export search results formated as you wish

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

Can you explain why you are doing this ? What is the heavy forwarder sending to ?

If you want to export data, use a scheduled search to export search results formated as you wish

0 Karma

yannK
Splunk Employee
Splunk Employee

if the answer suits you, you can accept it.

0 Karma

yannK
Splunk Employee
Splunk Employee

Here is the method to add any metadata (like host) in the events.
Do that at the indexer level (during index time)

http://splunk-base.splunk.com/answers/40848/how-can-i-rewriteadd-info-from-metadata-to-the-contents-...

0 Karma

kml_uvce
Builder

The actual scenario is like this: I am sending data like this...

universalforwarder -> indexer -> Heavy forwarder -> Syslog-ng server

How Can I get Universal forwarder machine address in Syslog-ng server.

kamal singh bisht
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...