Hello,
Which is the regex for the host field extraction (not cs_host, but the proxy IP address) used by the bluecoat:proxysg:access:syslog source type?
I found the one used for syslog source type in etc/system/default/transforms.props, but I need the specific one for bluecoat:proxysg:access:syslog source type.
Thank you very much.
I believe the configuration should be available $SPLUNK_HOME/etc/apps/Splunk_TA_bluecoat-proxysg
directory. Check both default and local directories inside this one.
Reference: http://docs.splunk.com/Documentation/AddOns/latest/BlueCoatProxySG/Configureinputs