Getting Data In

how can i add some description at all input log (metric, syslog, snmp, etc...)

melonking
Observer

 

how can i add some descriptions at all input log (metric, syslog, snmp, etc...)

 

i tried, add "_meta = description::test_description" in UF inputs.conf

in this case, can be added description at all log

but, cant HF case

 

so... i think, what if it could be applied to heavy forwarder?

retried add "_meta ~~" in HF inputs.conf

 

but, not work

 

how can i do? 

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "description"? If you manipulate _meta, you touch fields _for every event_ of given sourcetype, source or host.

But if you do want to add a static field to your events (I do it on some of my forwarders to be able to quickly identify which forwarder the data came from) you should also add the field as indexed field in your fields.conf on search-heads

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...