Getting Data In

can I pass additional source info from inputs.conf

jangid
Builder

Is it possible to pass extra info from inputs.conf?

e.g. [inputs.conf]

[default]
host = my_host

[monitor://somepath]
sourcetype = my_source
additional_info = my_additional_info

I want this additional info from all the forwarder, due to some reason I can not use host name.

Thanks

Tags (1)
0 Karma

sunrise
Contributor

You need to set custom fields. Reference below URL.
But this is not recommended by Splunk.
http://docs.splunk.com/Documentation/Splunk/5.0.3/Data/Configureindex-timefieldextraction

Generally you should use custom fields at search time, editing props.conf or transforms.conf.
http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsatsearchtime

0 Karma

jangid
Builder

this is my custom information. I want to add this information along with sourcetype and is should be searchable. similar to sourcetype, source and host.

0 Karma

linu1988
Champion

From the splunk documentation there is no additional parameters can be passed. But what is the difference between the sourcetype and additional_info? it's the same if we use in search.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...