I have a feed that has the host field defaulting to what is essentially the sourcetype, but in the shost field I have all the host data that I want/need in the host field. I want to know what is easier and won't break any of the splunk system configs for the built in host name extraction. Is it better to create a FIELDALIAS to have shost AS host in the props.conf for that dataset or to do something different like a transforms.conf?
Hi @robnewman666 i think, as you said, FIELDALIAS is better for this situation..
documentation reference:
https://docs.splunk.com/Documentation/Splunk/8.1.0/Knowledge/Configurefieldaliaseswithprops.conf