Getting Data In

how can i add some description at all input log (metric, syslog, snmp, etc...)

melonking
Observer

 

how can i add some descriptions at all input log (metric, syslog, snmp, etc...)

 

i tried, add "_meta = description::test_description" in UF inputs.conf

in this case, can be added description at all log

but, cant HF case

 

so... i think, what if it could be applied to heavy forwarder?

retried add "_meta ~~" in HF inputs.conf

 

but, not work

 

how can i do? 

 

 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

What do you mean by "description"? If you manipulate _meta, you touch fields _for every event_ of given sourcetype, source or host.

But if you do want to add a static field to your events (I do it on some of my forwarders to be able to quickly identify which forwarder the data came from) you should also add the field as indexed field in your fields.conf on search-heads

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...