Reporting

determine from which remote file data was indexed

bob87
Explorer

Hi

I am going to use splunk to index remote files using a universal forwarder. Is there a way to be able to tell from which data was indexed from which remote file? I have tried to index some files but did not get this information. In general i would like to index all files that are put in a directory, and not add files to monitor one by one

Any help is much appreciated

Tags (1)
0 Karma

dart
Splunk Employee
Splunk Employee

By default the source field should be the filename, what source does your data have?

bob87
Explorer

ok found what it was, i had set the input as TCP from Data inputs instead of configuring a receiver in Forwarding and receiving. Once I put the configuration in Forwarding and receiving I started getting the file name as the source

0 Karma

bob87
Explorer

the source field is tcp:

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...