Hello
I would like to add a tag to our Splunk clients by location.
I found how to create eventtypes on the server side but I am searching to tag all events directly on the client (in server.conf or inputs.conf maybe ?)
Is it doable ? If yes, what setting should I edit ?
Hi @romainbouajila,
the advantage to use eventtypes is that every updates has to be done in only one point, so if your hostnames chage you has to update only one eventtype.
Anyway, are you sure that your eventtyper change frequently? it's a strange thing!
If instead the problem is that you haven't a rule (e.g. italian servers tart with IT), you can list all the hosts of a group. e.g. eventtype italian_HT will be:
(host=server1 OR host=server3 OR host=server4)
as I said, if your list will change, you have to update only one eventtype.
Otherwise, you could use a lookup correlating each host to a tag, but in this way you have to manage the lookup, in my opinion the choice dependa on the user that has to manage the list:
Ciao.
Giuseppe
Hello,
This solution implies to maintain a list of all our hosts on the Search Head if we want them all to be in a defined "group".
Isn't it possible to tag all logs from the client side ? (maybe tag is not the appropriate setting)
Hi @romainbouajila,
the way to tag events is very easy, this is the process for one group, that you can repeat for more groups:
In this way you can create a search calling tags (e.g. you can call all the italian hosts using a simple search tag=IT).
I used this approach for an app that classifies all the login, logout and logfail events:
Ciao.
Giuseppe
Thank you for your answer.
My issue is that we change many times naming convention for our servers, so I can't use the hostnames to identify location.
Since we have no pattern in hostnames or ip ranges for location, I am afraid of the maintainability of this solution (at every new server, edit the eventtype search to add it)
I would like to be able to deploy it from the client side, at the vm creation. What would be the appropriate solution for this case ?
Should I stick to tags or should I check how to add metadata ?
Hi @romainbouajila,
the advantage to use eventtypes is that every updates has to be done in only one point, so if your hostnames chage you has to update only one eventtype.
Anyway, are you sure that your eventtyper change frequently? it's a strange thing!
If instead the problem is that you haven't a rule (e.g. italian servers tart with IT), you can list all the hosts of a group. e.g. eventtype italian_HT will be:
(host=server1 OR host=server3 OR host=server4)
as I said, if your list will change, you have to update only one eventtype.
Otherwise, you could use a lookup correlating each host to a tag, but in this way you have to manage the lookup, in my opinion the choice dependa on the user that has to manage the list:
Ciao.
Giuseppe