<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rename host field in event in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Rename-host-field-in-event/m-p/32838#M5852</link>
    <description>&lt;P&gt;My events have a field like this:&lt;/P&gt;

&lt;P&gt;host=192.168.0.0:8080&lt;/P&gt;

&lt;P&gt;I would like to leave the default host field that splunk assigns, but take the host field from the event and rename it to something like event_host.  &lt;/P&gt;

&lt;P&gt;How would do I do that?&lt;/P&gt;</description>
    <pubDate>Tue, 13 Nov 2012 18:07:04 GMT</pubDate>
    <dc:creator>tpederson</dc:creator>
    <dc:date>2012-11-13T18:07:04Z</dc:date>
    <item>
      <title>Rename host field in event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Rename-host-field-in-event/m-p/32838#M5852</link>
      <description>&lt;P&gt;My events have a field like this:&lt;/P&gt;

&lt;P&gt;host=192.168.0.0:8080&lt;/P&gt;

&lt;P&gt;I would like to leave the default host field that splunk assigns, but take the host field from the event and rename it to something like event_host.  &lt;/P&gt;

&lt;P&gt;How would do I do that?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2012 18:07:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Rename-host-field-in-event/m-p/32838#M5852</guid>
      <dc:creator>tpederson</dc:creator>
      <dc:date>2012-11-13T18:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rename host field in event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Rename-host-field-in-event/m-p/32839#M5853</link>
      <description>&lt;P&gt;Probalby the easiest way to do this would be to use the interactive field extractor.  You can bring it up by clicking on the green arrow to the left of the event and select "extract fields".&lt;/P&gt;

&lt;P&gt;This is a short video that demonstrates the usage:&lt;BR /&gt;
&lt;A href="http://www.splunk.com/view/SP-CAAADUY"&gt;http://www.splunk.com/view/SP-CAAADUY&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If this doesn't work then we can try some other options....&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2012 18:38:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Rename-host-field-in-event/m-p/32839#M5853</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2012-11-13T18:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Rename host field in event</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Rename-host-field-in-event/m-p/32840#M5854</link>
      <description>&lt;P&gt;That worked great, thanks for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2012 18:47:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Rename-host-field-in-event/m-p/32840#M5854</guid>
      <dc:creator>tpederson</dc:creator>
      <dc:date>2012-11-13T18:47:24Z</dc:date>
    </item>
  </channel>
</rss>

