Getting Data In

Is there a unique ID assigned to each forwarder to help me determine from which forwarder certain indexed data belongs to?

sakarunanitk
Explorer

Hi,

I have set up multiple forwarders sending events to a remote indexer. I am going to use the indexed data for further processing,. I wanted to know if there is a unique id assigned to each forwarder which will help me in knowing from which forwarder that indexed data belongs to.

Thanks,
Saravana Prabhu K

0 Karma

mcronkrite
Splunk Employee
Splunk Employee

You can add any value you want as an indexed field. You need to setup a WRITE_META in a props/transform like this.

props.conf

[mysourcetype]
TRANSFORMS-add_hostfwd = add_indexedfield

transforms.conf

[add_indexedfield]
WRITE_META = true
DEST_KEY = _meta
FORMAT = host_forwarder::$1
DEFAULT_VALUE = 123

fields.conf

[host_forwarder]
INDEXED = true

http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/Configureindex-timefieldextraction

But
You shouldn't run multiple forwarders on the same host, instead use index and sourcetypes in your inputs to segregate data or accept data from different inputs. The universal forwarder can listen on many ports, so lots of options around using the multiple instances.

0 Karma

sakarunanitk
Explorer

Thanks for the update

0 Karma

somesoni2
Revered Legend

Each forwarder will be assigned a "host" name and by default the same "host" (metadata) field will be available in all events/indexed data. The host field value may get updated (using transform/host regex on inputs.conf etc.) depending upon your configuration setup.

sakarunanitk
Explorer

Thanks for the info. But if there are multiple forwarders running on the same host?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...