Getting Data In

Change a sourcetypes 'host' field to read from the 'shost' field instead.

robnewman666
Path Finder

I have a feed that has the host field defaulting to what is essentially the sourcetype, but in the shost field I have all the host data that I want/need in the host field.  I want to know what is easier and won't break any of the splunk system configs for the built in host name extraction. Is it better to create a FIELDALIAS to have shost AS host in the props.conf for that dataset or to do something different like a transforms.conf?

Labels (3)
Tags (2)
0 Karma

soutamo
SplunkTrust
SplunkTrust
Probably I don’t get what you are meaning, but as host field is one of those indexed fields I prefer to put the real host there.
0 Karma

inventsekar
Super Champion

Hi @robnewman666 i think, as you said, FIELDALIAS is better for this situation.. 

documentation reference: 

https://docs.splunk.com/Documentation/Splunk/8.1.0/Knowledge/Configurefieldaliaseswithprops.conf

 

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!