We send data to Splunk Cloud from Universal Forwarder. I want to add _meta to each event sent to the Splunk Cloud.
I've added _meta to each stanza in the inputs.conf and restarted the Forwarder, but the meta does not appear in the Splunk Cloud
host = HOSTNAME
index = INDEX
source = SOURCE
# Monitor NGINX Logs
disabled = false
sourcetype = SOURCETYPE
_meta = region::sae1
What could I miss? Is it possible to add the meta without changes in the Splunk Cloud?
I think you may still need to update fields.conf on Splunk Cloud with
INDEXED = true
in order for Splunk to know that it is an indexed field.
Can it be done in Splunk Cloud user interface?