<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regex for host field inputs.conf in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29948#M6055</link>
    <description>&lt;P&gt;Anyone with ideas on how to convert this rex search string into host_regex= input for the Host field, to be a host name in inputs.conf.&lt;/P&gt;

&lt;P&gt;rex "(?P&amp;lt;App&amp;gt;\S+)__(?P&amp;lt;Loc&amp;gt;\S+)__(?P&amp;lt;Host&amp;gt;\S+)__(?P&amp;lt;PID&amp;gt;\d+)."&lt;/P&gt;</description>
    <pubDate>Thu, 09 Aug 2012 00:17:21 GMT</pubDate>
    <dc:creator>conner9</dc:creator>
    <dc:date>2012-08-09T00:17:21Z</dc:date>
    <item>
      <title>Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29948#M6055</link>
      <description>&lt;P&gt;Anyone with ideas on how to convert this rex search string into host_regex= input for the Host field, to be a host name in inputs.conf.&lt;/P&gt;

&lt;P&gt;rex "(?P&amp;lt;App&amp;gt;\S+)__(?P&amp;lt;Loc&amp;gt;\S+)__(?P&amp;lt;Host&amp;gt;\S+)__(?P&amp;lt;PID&amp;gt;\d+)."&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2012 00:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29948#M6055</guid>
      <dc:creator>conner9</dc:creator>
      <dc:date>2012-08-09T00:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29949#M6056</link>
      <description>&lt;P&gt;It's not really possible to answer your question without a data sample showing a string from which you want to extract the value of 'host'. Also, is that string going to be found in the 'source' field of the event?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2012 04:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29949#M6056</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-08-09T04:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29950#M6057</link>
      <description>&lt;P&gt;I know it's a wreck, just looking for good ideas.&lt;/P&gt;

&lt;P&gt;Here are some of the myriad of possibilities:&lt;/P&gt;

&lt;P&gt;timing_manager_main____iccsfwint0001__13618.term&lt;BR /&gt;
HOSTNAME=iccsfwin0001&lt;/P&gt;

&lt;P&gt;target_diag_manager__optical__iccsint0001.log&lt;BR /&gt;
HOSTNAME=iccsint0001  &lt;/P&gt;

&lt;P&gt;target_diag_manager__Video__main-frame-int1__8783.term&lt;BR /&gt;&lt;BR /&gt;
HOSTNAME=main-frame-int1&lt;/P&gt;

&lt;P&gt;target_area_manager____main-frame-int2.log2&lt;BR /&gt;
HOSTNAME=main-frame-int2&lt;/P&gt;

&lt;P&gt;Timing_FEP____its-master2.log&lt;BR /&gt;
HOSTNAME=its-master2&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2012 22:01:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29950#M6057</guid>
      <dc:creator>conner9</dc:creator>
      <dc:date>2012-08-09T22:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29951#M6058</link>
      <description>&lt;P&gt;This is helpful, but just to be clear : These strings are part of the path to the source file?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2012 22:55:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29951#M6058</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-08-09T22:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29952#M6059</link>
      <description>&lt;P&gt;Nah, I wish it was that easy, these are the actual file names that I'm trying to extract the hostname from.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2012 23:03:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29952#M6059</guid>
      <dc:creator>conner9</dc:creator>
      <dc:date>2012-08-09T23:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29953#M6060</link>
      <description>&lt;P&gt;That's ok, when I said "path" I was being inclusive of the file name.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2012 23:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29953#M6060</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-08-09T23:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29954#M6061</link>
      <description>&lt;P&gt;I would suggest:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host_regex = _+([^_]+)(?:__\d+)?\.\w+$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;...but you should &lt;EM&gt;really&lt;/EM&gt; test this out against some data samples before rolling it out to production.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2012 23:15:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29954#M6061</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-08-09T23:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Regex for host field inputs.conf</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29955#M6062</link>
      <description>&lt;P&gt;Seems to be working perfectly, Thanks so much for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2012 20:08:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Regex-for-host-field-inputs-conf/m-p/29955#M6062</guid>
      <dc:creator>conner9</dc:creator>
      <dc:date>2012-09-11T20:08:38Z</dc:date>
    </item>
  </channel>
</rss>

