Getting Data In

Changing hostname from FQDN to shortname from syslog input

MasterOogway
Communicator

I have an issue with mixed hostnames being defined as FQDN and Shortnames when indexed from syslog on port 514. I require all hostnames to be Short. I am trying to define a transforms (or another method) to take only the shortname from the HOST field but have stumbled on how this is accomplished given the hostname is defined NOT from within the event string, but from the forwarding host. So there is nothing to build a Transforms around/against.

Is there a simple method to define a shortname (and not at seach time) as the data is indexed from syslog?

Tags (2)
0 Karma

iunderwood
Path Finder

I did something very similar for my Riverbed App, by using a pair of search-time transforms. The first takes the first element of the shortname ... but I also needed something to return a full IPv4 address. It does assume that hostnames do not begin with a number:

This is in props.conf:

REPORT-rbsh_hostname = rbsh_hostname
REPORT-rbsh_hostname_ip = rbsh_hostname_ip

This is in transforms.conf:

[rbsh_hostname]
SOURCE_KEY = host
REGEX = (?=[a-zA-Z])(?P<hostname>[^ ]+?)\.
FORMAT = hostname::$1

[rbsh_hostname_ip]
SOURCE_KEY = host
REGEX = (?=\d+\.\d+\.\d+\.\d+)(?P<hostname>[^$]+)
FORMAT = hostname::$1

This should be able to point you in the right direction.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...