There are already some proposals how this could maybe do. But to understand better your situation and which solution is best for you, we should know more about your needs, used tools, environment and what is your target for this. How you are collecting data? Are you managing all inputs? Have you some other tools where you have some kind of CMDB? How you are deploying inputs? Are you using Splunk's ARI? If you are managing all inputs then maybe the easiest way to add this is use _meta field on those inputs. Just add those values in all input stanzas and then you have those events in your data when it comes into Splunk indexers. Other options are just use e.g. tags when you are onboarding data sources into splunk as already mentioned. As you see there is many ways to do it, and without more information it's impossible to say how you should do it. r. Ismo
... View more