Splunk Enterprise

Adding meta without changing splunk cloud

ivaleev
Loves-to-Learn

We send data to Splunk Cloud from Universal Forwarder. I want to add _meta to each event sent to the Splunk Cloud.

I've added _meta to each stanza in the inputs.conf and restarted the Forwarder, but the meta does not appear in the Splunk Cloud

 

 

[default]
host = HOSTNAME
index = INDEX
source = SOURCE

# Monitor NGINX Logs
[monitor:///var/log/nginx/access.json.log]
disabled = false
sourcetype = SOURCETYPE
_meta = region::sae1
...

 

 

 

What could I miss? Is it possible to add the meta without changes in the Splunk Cloud?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi,

I think you may still need to update fields.conf on Splunk Cloud with

[region]
INDEXED = true

in order for Splunk to know that it is an indexed field.

(https://docs.splunk.com/Documentation/Splunk/latest/Admin/Fieldsconf)

 

0 Karma

ivaleev
Loves-to-Learn

Can it be done in Splunk Cloud user interface?

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...