Getting Data In

stanza's for props.conf

pchintha
Engager

Hi,

We are having bunch of HFs in our environment from HFs we have confusion from which HF is getting the data, so to find easily we have to right stanza in props.conf in defaults/local. So based on this what is the stanza i can right

Example fields: splunk_HF
                                indextime

 

Labels (1)
0 Karma

kvnpichon
Path Finder

Hi,

If you search logs from the SH, the field "host" (Splunk default field) is the source host from which the event originated. 

Hope it helps

0 Karma

bhargavi
Path Finder

Hi @pchintha ,

Could you please elaborate on your requirement. 

0 Karma

pchintha
Engager

@bhargavi 

we are having example 50 HF`s from these HF`s sending logs to Indexers right, so while searching in SH from which HF we are getting the logs for this do we can right some stanzas in props.conf to extract the HF`s field to find easily. What stanzas will help to get solution.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...