Hi all 🙂
I'm in trouble regarding set host in multiple logs files ...
Here's folders logs:
/192.168.0.1/log1.log
/192.168.0.2/log1.log
/192.168.0.3/log1.log
For example, an log1.log:
<166>2012-03-04T11:02:14.526Z MyHost Vpxa: [34229B90 verbose 'SoapAdapter.HTTPService' opID=SWI-3f235b28-23]
I'd like to catch "MyHost" in each log1.log to set host value.
Thanks for your help
Regards
could you please post your inputs.conf
/k
Not work 😞
Host still appear with "192.168.0.1" 192.168.0.2" etc.
Thanks 🙂
Hi,
Have you tried to set the sourcetype to syslog
, since that is what it seems to be. Splunk should then extract the hostname from each event by default, I think.
/kristian