<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Original_host in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685507#M19241</link>
    <description>&lt;P&gt;in the props.conf, the original_host extraction won't work for the majority of users&amp;nbsp; - EXTRACT-original_host = \d+-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d+[\+\-]\d{2}:\d{2}\s(?&amp;lt;original_host&amp;gt;\S+)&lt;/P&gt;&lt;P&gt;original_host is I believe a crucial fiield, so all datamodels can work as expected&lt;/P&gt;</description>
    <pubDate>Thu, 25 Apr 2024 18:04:58 GMT</pubDate>
    <dc:creator>Kiko</dc:creator>
    <dc:date>2024-04-25T18:04:58Z</dc:date>
    <item>
      <title>Original_host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685494#M19239</link>
      <description>&lt;P&gt;Original_host Filed extraction should be aligned if a Syslog server have different date/time format. The current filed extraction is defined based on your syslog server and I am positive that this app works only for a couple of Splunk customers.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 15:29:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685494#M19239</guid>
      <dc:creator>Kiko</dc:creator>
      <dc:date>2024-04-25T15:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Original_host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685506#M19240</link>
      <description>&lt;P&gt;Honestly? I have no idea what you're talking about. Could you be more specific?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 17:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685506#M19240</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-25T17:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Original_host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685507#M19241</link>
      <description>&lt;P&gt;in the props.conf, the original_host extraction won't work for the majority of users&amp;nbsp; - EXTRACT-original_host = \d+-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d+[\+\-]\d{2}:\d{2}\s(?&amp;lt;original_host&amp;gt;\S+)&lt;/P&gt;&lt;P&gt;original_host is I believe a crucial fiield, so all datamodels can work as expected&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 18:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685507#M19241</guid>
      <dc:creator>Kiko</dc:creator>
      <dc:date>2024-04-25T18:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Original_host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685509#M19242</link>
      <description>&lt;P&gt;Ok. We have no context. You're writing as if we were supposed to know what you are talking about. You're posting in a Splunk Enterprise section of this forum, which is meant for questions specific to on-premise software functionality and issues. But you selected a specific add-on as a product you're referring to. In such case you should have posted in the 'All Apps and Add-ons' section. We do not have glass orbs and don't know what you mean &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 18:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Original-host/m-p/685509#M19242</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-04-25T18:16:59Z</dc:date>
    </item>
  </channel>
</rss>

