Knowledge Management

Tags - Auto tagging from a csv

jnguyen413
New Member

Looking to see if this is possible or if there are any other alternatives.

Goal: I am using tags as a search filter for role access and I am looking for an automated way to manage this. Servers may be decommissioned or new servers may pop up so I want to automate as much as possible. An example would be providing an application owners access to ONLY OS logs, web server logs, etc to their application only.

Background: We have indexes for windows logs, unix logs, web server logs, etc, so we cannot have separate indexes for applications. We have an automated job to produce a csv from our CMDB that tells us what application is mapped to which server, so how can we use that to auto-tag?

0 Karma

HighJustice
Engager

I would recommend to use either automatic lookups or define an event types with proper tags to have an "automatic tagging"

sloshburch
Splunk Employee
Splunk Employee

No trivial way to auto-tag that I can think of. I think an alternate approach would be to use lookups to associate other fields with those events.

Although, if you have a criteria for determining a tag association within a csv, then you can use that same info to define eventtypes and therefore tags...

Feel free to post a scrubbed example and we get make this question more tangible.

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...