Getting Data In

Many indexes for many hosts? (no hostname in the logs)

Cesaredf
Explorer

Hi all,

I have a doubt about which can be the best practice about indexing if:

  • I have several splunk client forwarding to the same splunk server the same logs folder. Each night the logs are updated but no logs contain the host name to distinguish among them.

Now my doubt/question is: should I use different indexes per hosts? in such a case a could use different clones of the same app on each host right?

Does anybody has a better how-to or best practice?

Many thanks in advance Cdf.

Tags (1)
0 Karma

satishsdange
Builder

You can mention hostname in inputs.conf as shown below -

[default]
host = cisco_router1

[monitor:///opt/log/cisco_router1/cisco_ironport_web.log]

So that whenever indexer receives data from UF, it will have hostname.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...