Getting Data In

HEC (HTTP Event Collector) host rename using props transforms - ansible tower

merrelr
Path Finder

I've setup HEC on a heavy forwarder to gather logs through HEC for Ansible Tower.

Logs are rolling in, but I can't seem to get props/transforms setup correctly to rename the hostname from IP to text.

props.conf

[host::$ipaddress]  
TRANSFORMS-$hostname_rename = host_rename_$hostname

transforms.conf

[host_rename_$hostname]
REGEX = (.*)
DEST_KEY = MetaData:Host
FORMAT = host::$hostname

I've applied these setting to both the HF and to my Indexer cluster and neither place renames the hostname from IP address to text.

Is there something special with HEC or HF that's preventing these changes from taking place?

0 Karma

darrenfuller
Contributor

HI Merreir,

Which endpoint are you using to connect to your HEC? /services/collector or /services/collector/event or /services/collector/raw ?

Only data going through /services/collector/event will get affected by props / transforms.

Hope this helps...
./D

0 Karma

harsmarvania57
Ultra Champion

Not /services/collector/event endpoint, if you want to parse data using props/transforms then you need to use /services/collector/raw endpoint.

0 Karma

merrelr
Path Finder

I'll give that a try and see if I can get it to work that way.

0 Karma

merrelr
Path Finder

I had to update the props to use 127.0.0.1 instead of it's actual IP. I'm not sure what changed since yesterday with my testing.

I left the endpoint as /services/collector/event and my props/transforms are working.

props.conf

[host::127.0.0.1]
TRANSFORMS-$hostname_rename = host_rename_$hostname

transforms.conf

[host_rename_$hostname]
REGEX = (.*)
DEST_KEY = MetaData:Host
FORMAT = host::$hostname

0 Karma

merrelr
Path Finder

I'm using the "/services/collector/event" endpoint.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...