I have an Event with no Splunk Metadata value within the events and i am trying to add new fields such as host, index,source and sourcetype . custom fields and i tried using an eval but no luck, how do i go about this ?
You can also set metadata within the Source itself under "Fields". This can be handy if the source events are all going to the same place since you can set and forget.