Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Assigning custom metadata fields during a one-time input of data

$
0
0

I use splunk to analyze log data associated with a support ticket. When I import data into splunk from a log tarball, I would like to add a field to all events indicating the original tar file it was extracted from. Like this: filename = mylogtarball.tgz

I want this field applied to all events that result from the tarball extraction and import. But of course, when I uploaded anotherlogdir.tgz, I want the filename field for those events to show the correct value there.

Any thoughts on how I could make this happen?


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>