<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: setting hostname via syslog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/setting-hostname-via-syslog/m-p/28993#M4995</link>
    <description>&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/38284/how-do-i-set-hostname-without-syslog"&gt;http://splunk-base.splunk.com/answers/38284/how-do-i-set-hostname-without-syslog&lt;/A&gt;&lt;BR /&gt;
-inputs.conf&lt;/P&gt;

&lt;P&gt;[monitor:///var/log/HOSTS/...]&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;followTail = 0&lt;/P&gt;

&lt;P&gt;sourcetype = syslog&lt;/P&gt;

&lt;P&gt;-props.conf&lt;/P&gt;

&lt;P&gt;[ syslog ]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-t1 = rename_host&lt;/P&gt;

&lt;P&gt;-transforms.conf&lt;/P&gt;

&lt;P&gt;[rename_host]&lt;/P&gt;

&lt;P&gt;REGEX = s_local@([^s]+)&lt;/P&gt;

&lt;P&gt;FORMAT = host::$1&lt;/P&gt;

&lt;P&gt;DEST_KEY = MetaData:Host&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2013 17:56:25 GMT</pubDate>
    <dc:creator>davecroto</dc:creator>
    <dc:date>2013-08-08T17:56:25Z</dc:date>
    <item>
      <title>setting hostname via syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-hostname-via-syslog/m-p/28992#M4994</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a feed that is collecting data and resending it to Splunk via syslog. I'd like to extract the hostname from the message, not the device sending the message. &lt;/P&gt;

&lt;P&gt;If my feed was like this, and I wanted to extract it from agentmachine=... (up to the next pipe, but no $), how would I do that?&lt;/P&gt;

&lt;P&gt;2013-08-08T11:06:40-04:00 1.2.3.4 blahblahblah eventid=675|agentmachine=XXX\AAAAA$|auditmachine=|category=9|ClientDomain=|clientUser=SDFSDF|clientlogonid=0|clientsid=S-1-5-21-1343024091-606747145-1801674531-1091404|collectiontime=8/8/2013 3:06:37 PM|creationtime=8/8/2013 3:06:36 PM|flags=1|headerDomain=AAAA|headersid=S-1-5-18|headeruser=SYSTEM|Primarydomain=|PrimaryLogonID=0|primarysid=|primaryuser=|targetDomain=|targetsid=|targetuser=|sequenceno=3514421565|source=Security|string01=krbtgt/BMI|string02=0x0|string03=0x19|string04=1.2.3.4|string05=|string06=|string07=|string08=|string09=|string10=|string11=|string12=|string13=|string14=|string15=|string16=|string17=|string18=|string19=|string20=|string21=|string22=|type=16|listenerName=AD-Kerberos-PreAuthFailed&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2013 15:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-hostname-via-syslog/m-p/28992#M4994</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2013-08-08T15:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: setting hostname via syslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setting-hostname-via-syslog/m-p/28993#M4995</link>
      <description>&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/38284/how-do-i-set-hostname-without-syslog"&gt;http://splunk-base.splunk.com/answers/38284/how-do-i-set-hostname-without-syslog&lt;/A&gt;&lt;BR /&gt;
-inputs.conf&lt;/P&gt;

&lt;P&gt;[monitor:///var/log/HOSTS/...]&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;followTail = 0&lt;/P&gt;

&lt;P&gt;sourcetype = syslog&lt;/P&gt;

&lt;P&gt;-props.conf&lt;/P&gt;

&lt;P&gt;[ syslog ]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-t1 = rename_host&lt;/P&gt;

&lt;P&gt;-transforms.conf&lt;/P&gt;

&lt;P&gt;[rename_host]&lt;/P&gt;

&lt;P&gt;REGEX = s_local@([^s]+)&lt;/P&gt;

&lt;P&gt;FORMAT = host::$1&lt;/P&gt;

&lt;P&gt;DEST_KEY = MetaData:Host&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2013 17:56:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setting-hostname-via-syslog/m-p/28993#M4995</guid>
      <dc:creator>davecroto</dc:creator>
      <dc:date>2013-08-08T17:56:25Z</dc:date>
    </item>
  </channel>
</rss>

