<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: get host from fileshare in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/get-host-from-fileshare/m-p/20386#M162</link>
    <description>&lt;P&gt;Could you try host_regex like as bellow? It will work for your requirement. &lt;/P&gt;

&lt;P&gt;[monitor://xxxxxxxxxxx]&lt;BR /&gt;
host_regex = (server\d+)&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2011 05:13:48 GMT</pubDate>
    <dc:creator>Takajian</dc:creator>
    <dc:date>2011-11-22T05:13:48Z</dc:date>
    <item>
      <title>get host from fileshare</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/get-host-from-fileshare/m-p/20385#M161</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have multiple inputs.conf entries&lt;BR /&gt;
...&lt;BR /&gt;
[monitor://\\server1\share$\mylog.log]&lt;BR /&gt;
sourcetype = MYLOG&lt;BR /&gt;
index = mylog&lt;BR /&gt;
host_segment = 1&lt;BR /&gt;
...&lt;BR /&gt;
this creates host = share$ on index server...&lt;BR /&gt;
changing to host_segment = 0 did not work.&lt;BR /&gt;
how can I get hostname out of fileshare (\\server\share$\log)?&lt;/P&gt;

&lt;P&gt;please help.&lt;/P&gt;

&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/get-host-from-fileshare/m-p/20385#M161</guid>
      <dc:creator>nurtdi</dc:creator>
      <dc:date>2020-09-28T10:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: get host from fileshare</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/get-host-from-fileshare/m-p/20386#M162</link>
      <description>&lt;P&gt;Could you try host_regex like as bellow? It will work for your requirement. &lt;/P&gt;

&lt;P&gt;[monitor://xxxxxxxxxxx]&lt;BR /&gt;
host_regex = (server\d+)&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2011 05:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/get-host-from-fileshare/m-p/20386#M162</guid>
      <dc:creator>Takajian</dc:creator>
      <dc:date>2011-11-22T05:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: get host from fileshare</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/get-host-from-fileshare/m-p/20387#M163</link>
      <description>&lt;P&gt;Thank you for your answer. Although it did not work... &lt;BR /&gt;
The solution was quite simple - I just needed to use static host = server1 in each stanza.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2011 12:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/get-host-from-fileshare/m-p/20387#M163</guid>
      <dc:creator>nurtdi</dc:creator>
      <dc:date>2011-11-22T12:59:13Z</dc:date>
    </item>
  </channel>
</rss>

