- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jelli5518
Engager
11-05-2019
01:04 PM
Log files are list this:
/audit/files/any/path/host1.audittype-secure.timestamp.audit.log.1
/audit/files/hostab.audittype-audit.timestamp.txt
etc...
Example:
/audit/files/path/host123.secure.2019080165784.audit.log.1
I want Splunk to have host as "host1" and "hostab" and "host123", and etc..
I have this in inputs.conf:
[monitor:///audit/files]
host_regex = \/S+([^.]).*
But it isn't working at all.
I'm trying to set hostname to the string between the last / and the first.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/d02c8/d02c884d8b9721445f10572fd724ddd6caaa8cde" alt="mayurr98 mayurr98"
mayurr98
Super Champion
11-05-2019
02:00 PM
try this :
host_regex = .*\/(host[^\.]+).*
OR
host_regex = \/(host[^\.]+)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/d02c8/d02c884d8b9721445f10572fd724ddd6caaa8cde" alt="mayurr98 mayurr98"
mayurr98
Super Champion
11-05-2019
02:00 PM
try this :
host_regex = .*\/(host[^\.]+).*
OR
host_regex = \/(host[^\.]+)
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jelli5518
Engager
11-06-2019
09:02 AM
The first worked!
The second put the path in the hostname.
Seems like I needed to remove the "host" keyboard from the above. I'm using Splunk Enterprise 7.1.2, if that matters.
Thanks!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/d02c8/d02c884d8b9721445f10572fd724ddd6caaa8cde" alt="mayurr98 mayurr98"
mayurr98
Super Champion
11-06-2019
09:24 AM
You are welcome!
Yeah .*\/([^\.]+).*
will also work. Please accept the answer if it works for you to close the question.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
jelli5518
Engager
11-06-2019
09:37 AM
My log files don't actually have the word "host" in them-- that was just an example. Thanks again!
data:image/s3,"s3://crabby-images/5d9f8/5d9f80c54160124d38856b77a799077db7d57026" alt=""