Getting Data In

Question regarding _meta on multi-tenant hosts

dfurtaw
Path Finder

Hey guys,

 

I had a quick question that I am unable to get an answer for by googling/doc'ing. If I am wanting to tag a server by using /etc/system/local/inputs.conf, am I able to apply this _meta field to various sources as opposed to only sourcetypes?

 

For example, we are needing to give specific tags to each respective log file location on a server. One location, will have _meta = altci::examplea and the other will have _meta = altci::exampleb.

 

It would look like this:

 

[default]

hostname = $decideOnStartUp

 

[F:\logFiles\inetpub\*.log]

_meta = altci:examplea

 

[C:\logFiles\inetpub\*.log]

_meta = altci:exampleb

 

Reason being is a few of our servers are legacy and host numerous sites/apps. Blah. I know it sucks, but it's a few old servers that are pretty important!

 

Thanks!!

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...