Getting Data In

how can i add some description at all input log (metric, syslog, snmp, etc...)

melonking
Observer

 

how can i add some descriptions at all input log (metric, syslog, snmp, etc...)

 

i tried, add "_meta = description::test_description" in UF inputs.conf

in this case, can be added description at all log

but, cant HF case

 

so... i think, what if it could be applied to heavy forwarder?

retried add "_meta ~~" in HF inputs.conf

 

but, not work

 

how can i do? 

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "description"? If you manipulate _meta, you touch fields _for every event_ of given sourcetype, source or host.

But if you do want to add a static field to your events (I do it on some of my forwarders to be able to quickly identify which forwarder the data came from) you should also add the field as indexed field in your fields.conf on search-heads

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...