Getting Data In

Change hostname transform

BryanBerry
Path Finder

We have a host where logs are aggregated already. I want to Splunk these logs. The source host for the logs is in the file path. I attempted the below props/transforms as a PoC, but no luck. Can anyone catch what I'm doing wrong?

transforms.conf:

[foobar]
SOURCE_KEY = MetaData:Source
DEST_KEY = MetaData:Host
REGEX = ^/opt/splunk/v(ar)
FORMAT = host::bogus$1

props.conf:

[boguslog]
TRANSFORMS-foo=foobar

inputs.conf:

[monitor:///opt/splunk/var/log/splunk/splunkd.log]
sourcetype = boguslog

Also, would this sort of transformation work on a UF or only a HF? I was originally doing this to test for myself, but I can't get it to work on my HF in the first place.

0 Karma
1 Solution

Ayn
Legend

Umm, aren't you making this a bit too difficult? Did you have a look at the host_segment configuration directive in inputs.conf?

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

View solution in original post

Ayn
Legend

Umm, aren't you making this a bit too difficult? Did you have a look at the host_segment configuration directive in inputs.conf?

http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

BryanBerry
Path Finder

You, sir, are kind of awesome. Using this with the UF actually shaves two weeks off my project by avoiding the heavy forwarder. Thank you!

0 Karma

JSapienza
Contributor

Correct behavior, props and transforms are not processed by a UF .

0 Karma

BryanBerry
Path Finder

Fixed the transform, thanks to http://splunk-base.splunk.com/answers/24769/host-override.

The ^ in my regex was mucking things up. The MetaData:Source source begins with text "source::". Removing the ^ to permit the "source::" at the start of the value fixed it.

Still haven't gotten it to work on my UF though. Am I correct in understanding that this does not work on the UF?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...