<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to recognize hostname from source in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393037#M6135</link>
    <description>&lt;P&gt;Are you working on an all-in-one Splunk instance or a distributed environment?&lt;/P&gt;

&lt;P&gt;I would also check my inputs.conf to see if a host=127.0.0.1 parameter was also defined for the path you want to monitor.&lt;/P&gt;</description>
    <pubDate>Tue, 28 May 2019 15:28:53 GMT</pubDate>
    <dc:creator>uhaq</dc:creator>
    <dc:date>2019-05-28T15:28:53Z</dc:date>
    <item>
      <title>Unable to recognize hostname from source</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393036#M6134</link>
      <description>&lt;P&gt;My data consists of a hierarchical zip file. Although the hostname is always located in the fifth and last segment of the path, entering 5 at index time for "Segment in path" did not work. Instead, the host is always displayed as 127.0.0.1. &lt;BR /&gt;
For reference, the source path looks similar to this: &lt;STRONG&gt;files.zip:./files/dir/logs/hostname&lt;/STRONG&gt;&lt;BR /&gt;
I have also tried many other numbers, including -1 in the hope that it could count backwards.&lt;BR /&gt;
Even when uploading one &lt;STRONG&gt;single log file&lt;/STRONG&gt; which just has the hostname as the filename, and entering segment in path = 1, the hostname was not recognised.&lt;BR /&gt;
I don't have access to edit props.conf, transforms.conf etc., so it would need to work from the web interface.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 14:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393036#M6134</guid>
      <dc:creator>splunklearner12</dc:creator>
      <dc:date>2019-05-28T14:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to recognize hostname from source</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393037#M6135</link>
      <description>&lt;P&gt;Are you working on an all-in-one Splunk instance or a distributed environment?&lt;/P&gt;

&lt;P&gt;I would also check my inputs.conf to see if a host=127.0.0.1 parameter was also defined for the path you want to monitor.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 15:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393037#M6135</guid>
      <dc:creator>uhaq</dc:creator>
      <dc:date>2019-05-28T15:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to recognize hostname from source</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393038#M6136</link>
      <description>&lt;P&gt;I have found a workaround by creating a field transformation with the below regex, and a corresponding field extraction.&lt;BR /&gt;
files.zip:./files/.*/.*/(?&amp;amp;lthostname&amp;amp;gt[\w-]*)&lt;BR /&gt;
Then, created an alias for hostname AS host, i.e. overwriting field values.&lt;BR /&gt;
It's not ideal because now the search for the host is doubled up in two fields, so I'm still interested if there's a solution for the segment in path method at index time.&lt;BR /&gt;
 - Sorry for all the edits, I had to figure out how to display &amp;amp;lt, &amp;amp;gt and *&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 15:36:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393038#M6136</guid>
      <dc:creator>splunklearner12</dc:creator>
      <dc:date>2019-05-28T15:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to recognize hostname from source</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393039#M6137</link>
      <description>&lt;P&gt;Yes, it's single instance.&lt;BR /&gt;
There was a line saying host=splunk in local/inputs.conf which I deleted and then restarted splunk, but it made no difference. I found in the web app server settings &amp;gt; general settings that a default host was set to splunk, which I deleted and then restarted, but after restarting the setting just reappeared. The segment in path still doesn't work.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2019 08:47:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Unable-to-recognize-hostname-from-source/m-p/393039#M6137</guid>
      <dc:creator>splunklearner12</dc:creator>
      <dc:date>2019-05-29T08:47:28Z</dc:date>
    </item>
  </channel>
</rss>

