All Apps and Add-ons

Is there no "Host Field value" setting in Splunk DB Connect 2?

Explorer

I use the Host Field in most of my searches. Splunk DB Connect 1 had a setting to add the Host Field value to events that are imported from Oracle. There seems to be no equivalent setting in Splunk DB Connect 2. Am I missing something? If there really is no equivalent setting, can I inject a Host Field using a Transform?

1 Solution

Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

View solution in original post

Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host

View solution in original post

Path Finder

Awesome, thanks. They have hidden it like a treasure.

0 Karma

Explorer

Ahh, now that I see it, it makes perfect sense. Thank you.

0 Karma

Splunk Employee
Splunk Employee

No problem, please accept if this answers your question. Thanks!

0 Karma

Explorer

Where do I find that series of links? Or is it a document reference? I see nothing that resembles that.

My current environment:

Splunk Version ............................................6.1.5
Splunk Build ............................................239630
Current App ............................................Splunk DB Connect v2
App Version ............................................2.0.4
App Build ............................................270621

0 Karma

Splunk Employee
Splunk Employee

Go to: Settings -> Data inputs -> Splunk DB Connect input Service -> New OR name of existing input -> More Settings (at the bottom) -> Host