All Apps and Add-ons

Is there no "Host Field value" setting in Splunk DB Connect 2?

nysoitsmiket
Explorer

I use the Host Field in most of my searches. Splunk DB Connect 1 had a setting to add the Host Field value to events that are imported from Oracle. There seems to be no equivalent setting in Splunk DB Connect 2. Am I missing something? If there really is no equivalent setting, can I inject a Host Field using a Transform?

1 Solution

jnussbaum_splun
Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

View solution in original post

jnussbaum_splun
Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

teekayx
Path Finder

Awesome, thanks. They have hidden it like a treasure.

0 Karma

nysoitsmiket
Explorer

Ahh, now that I see it, it makes perfect sense. Thank you.

0 Karma

jnussbaum_splun
Splunk Employee
Splunk Employee

No problem, please accept if this answers your question. Thanks!

0 Karma

nysoitsmiket
Explorer

Where do I find that series of links? Or is it a document reference? I see nothing that resembles that.

My current environment:

Splunk Version ............................................6.1.5
Splunk Build ............................................239630
Current App ............................................Splunk DB Connect v2
App Version ............................................2.0.4
App Build ............................................270621

0 Karma

jnussbaum_splun
Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...