<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with regex for inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636319#M108838</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can set host in inputs.conf on Universal Forwarders in fixed mode.&lt;/P&gt;&lt;P&gt;you can also override host field only on Indexers or (if present) on Heavy Forwarders following the instructions on&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Overridedefaulthostassignments" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Overridedefaulthostassignments&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 13:41:42 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-03-28T13:41:42Z</dc:date>
    <item>
      <title>Need help with regex for inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636316#M108837</link>
      <description>&lt;P&gt;Need help with regex for inputs.conf to change the host as hostname and incase host has FQDN it should pick up till hostname only&amp;nbsp;&lt;/P&gt;&lt;P&gt;example&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) host=hostname1&lt;/P&gt;&lt;P&gt;2) host = hostname2.yahoo.com&lt;/P&gt;&lt;P&gt;3) host = hostname3.google.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In all these example it should pick only hostname1,hostname2,hostname3&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636316#M108837</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2023-03-28T13:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with regex for inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636319#M108838</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can set host in inputs.conf on Universal Forwarders in fixed mode.&lt;/P&gt;&lt;P&gt;you can also override host field only on Indexers or (if present) on Heavy Forwarders following the instructions on&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Overridedefaulthostassignments" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Overridedefaulthostassignments&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:41:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636319#M108838</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-28T13:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with regex for inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636321#M108839</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your quick response.&lt;/P&gt;&lt;P&gt;The link shares details to perform at props.conf and transforms.conf. I am looking for changes in inputs.conf directly.&lt;BR /&gt;Can you help me on the same?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:50:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636321#M108839</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2023-03-28T13:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with regex for inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636325#M108841</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said, on inputs.conf you can only set up a value for host, evetually read from the path.&lt;/P&gt;&lt;P&gt;But if you want to have the FQDN for all Universal Forwarders, it's possible to configure the hostaneme to use FQDN adding this option to server.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;hostnameOption=fullyqualifiedname&lt;/LI-CODE&gt;&lt;P&gt;as you can read at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Admin/Serverconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Admin/Serverconf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;hostnameOption = [ fullyqualifiedname | clustername | shortname ]
* The type of information to use to determine how splunkd sets the 'host' value for a Windows
  Splunk platform instance when you specify an input stanza with 'host = $decideOnStartup'.
* Applies only to Windows hosts, and only for input stanzas that use the
  "host = $decideOnStartup" setting and value.
* Valid values are "fullyqualifiedname", "clustername", and "shortname".
* The value returned for the 'host' field depends on Windows DNS, NETBIOS,
  and what the name of the host is.
  * 'fullyqualifiedname' uses Windows DNS to return the fully qualified host name as the value.
  * 'clustername' also uses Windows DNS, but sets the value to the domain and machine name.
  * 'shortname' returns the NETBIOS name of the machine.
* Cannot be an empty string.
* Default: shortname&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 13:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636325#M108841</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-28T13:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with regex for inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636329#M108843</link>
      <description>&lt;P&gt;Thanks for sharing your input&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;.&lt;BR /&gt;I don't want to edit the server.conf for this requirement. I can only make changes in inputs.conf and for this I am following the below document section. Hence looking for regex&lt;BR /&gt;&lt;BR /&gt;link--&amp;gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Data/Setadefaulthostforaninput" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Data/Setadefaulthostforaninput&lt;/A&gt;&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;section--&amp;gt;Set the event host with the host_regex attribute&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/H3&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:12:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636329#M108843</guid>
      <dc:creator>AK_Splunk</dc:creator>
      <dc:date>2023-03-28T14:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with regex for inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636331#M108844</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as I said and it's described in the above link, you can statically configure a value for host,adding the host option to each stanza of inputs.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///your_path/your_file.log]
disabled = 0
index = your_index
sourcetype = your_sourcetype
host = your_host&lt;/LI-CODE&gt;&lt;P&gt;but it's a static assignment.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:20:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636331#M108844</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-28T14:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with regex for inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636332#M108845</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243360"&gt;@AK_Splunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;an additional information: you can extract the host from the path using the segment or a regex still on path or filename:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;host_regex = &amp;lt;regular expression&amp;gt;
* If specified, &amp;lt;regular expression&amp;gt; extracts host from the path to the file
  for each input file.
    * Detail: This feature examines the source key; if source is set
      explicitly in the stanza, that string is matched, not the original
      filename.
* Specifically, the first group of the regular expression (regex) is used
  as the host.
* If the regex fails to match, the input uses the default 'host' setting.
* If 'host_regex' and 'host_segment' are both set, the input ignores 'host_regex'.
* No default.

host_segment = &amp;lt;integer&amp;gt;
* If set to N, the Splunk platform sets the Nth "/"-separated segment of the path
  as 'host'.
    * For example, if you set "host_segment = 3" and the path is
      /logs/servers/host08/abc.txt, the third segment, "host08", is used.
* If the value is not an integer or is less than 1, the default 'host'
  setting is used.
* On Windows machines, the drive letter and colon before the backslash *does not*
  count as one segment.
    * For example, if you set "host_segment = 3" and the monitor path is
      D:\logs\servers\host01, Splunk software sets the host as "host01" because
      that is the third segment.
* No default.&lt;/LI-CODE&gt;&lt;P&gt;as described at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/admin/Inputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/admin/Inputsconf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-with-regex-for-inputs-conf/m-p/636332#M108845</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-28T14:23:31Z</dc:date>
    </item>
  </channel>
</rss>

