Hi,
We are having bunch of HFs in our environment from HFs we have confusion from which HF is getting the data, so to find easily we have to right stanza in props.conf in defaults/local. So based on this what is the stanza i can right
Example fields: splunk_HF
indextime
Hi,
If you search logs from the SH, the field "host" (Splunk default field) is the source host from which the event originated.
Hope it helps
Hi @pchintha ,
Could you please elaborate on your requirement.
we are having example 50 HF`s from these HF`s sending logs to Indexers right, so while searching in SH from which HF we are getting the logs for this do we can right some stanzas in props.conf to extract the HF`s field to find easily. What stanzas will help to get solution.