Splunk Dev

get host from fileshare

nurtdi
Path Finder

Hello,
I have multiple inputs.conf entries
...
[monitor://\\server1\share$\mylog.log]
sourcetype = MYLOG
index = mylog
host_segment = 1
...
this creates host = share$ on index server...
changing to host_segment = 0 did not work.
how can I get hostname out of fileshare (\\server\share$\log)?

please help.

thank you.

Tags (1)
1 Solution

nurtdi
Path Finder

Thank you for your answer. Although it did not work...
The solution was quite simple - I just needed to use static host = server1 in each stanza.
Thanks.

View solution in original post

0 Karma

nurtdi
Path Finder

Thank you for your answer. Although it did not work...
The solution was quite simple - I just needed to use static host = server1 in each stanza.
Thanks.

0 Karma

Takajian
Builder

Could you try host_regex like as bellow? It will work for your requirement.

[monitor://xxxxxxxxxxx]
host_regex = (server\d+)

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...