Getting Data In

How to create a new field with static value during index time

DataOrg
Builder

I want to append new field with static value to the data during index time.

how to create with props.conf/transform.conf and no field extraction is required

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can use INGEST_EVAL = foo="bar" in transforms.conf.

---
If this reply helps you, Karma would be appreciated.

DataOrg
Builder

worked directly adding on inputs.conf.

[script://path/your_script.py]
_meta = script_name::abc.py

0 Karma

adonio
Ultra Champion

why do you need to do this? what is the use case?
if you need that data all the time ... you can add ... | eval NEW_FIELD = "YOUR STATIC VALUE" ...

0 Karma
Get Updates on the Splunk Community!

Extending Splunk AI Assistant for SPL to Splunk Enterprise customers!

Howdy Splunk Community! It’s an exciting day here at Splunk – Splunk AI Assistant for SPL version 1.3.0 is now ...

Developer Spotlight with Qmulos

Qmulos: Building a Next-Level Cybersecurity Business through Splunk Apps Qmulos started as a scrappy startup ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...