All Apps and Add-ons

Is there no "Host Field value" setting in Splunk DB Connect 2?

nysoitsmiket
Explorer

I use the Host Field in most of my searches. Splunk DB Connect 1 had a setting to add the Host Field value to events that are imported from Oracle. There seems to be no equivalent setting in Splunk DB Connect 2. Am I missing something? If there really is no equivalent setting, can I inject a Host Field using a Transform?

1 Solution

jnussbaum_splun
Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

View solution in original post

jnussbaum_splun
Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

teekayx
Path Finder

Awesome, thanks. They have hidden it like a treasure.

0 Karma

nysoitsmiket
Explorer

Ahh, now that I see it, it makes perfect sense. Thank you.

0 Karma

jnussbaum_splun
Splunk Employee
Splunk Employee

No problem, please accept if this answers your question. Thanks!

0 Karma

nysoitsmiket
Explorer

Where do I find that series of links? Or is it a document reference? I see nothing that resembles that.

My current environment:

Splunk Version ............................................6.1.5
Splunk Build ............................................239630
Current App ............................................Splunk DB Connect v2
App Version ............................................2.0.4
App Build ............................................270621

0 Karma

jnussbaum_splun
Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...