Getting Data In

Host Override

carmackd
Communicator

I'm having trouble getting a host override to work. It appears Splunk is ignoring my transform (i assume because it's incorrect) and using the forwarder host value. My transform is sitting on the indexer, which is receiving the log source from a universal forwarder. The host value I'm trying to extract is in the file path, which is coming in as source.

Here is my transform:

[inhouseapp_override_host]
SOURCE_KEY=MetaData:Source
REGEX=source::^(?:\/[^\/]+){3}\/([^_]+)
FORMAT=host::$1
DEST_KEY=MetaData:Host

Here is the file path coming in as source:

/app/vault/inhouseapp/HostnameApp101_052011.log
1 Solution

dshpritz
SplunkTrust
SplunkTrust

Sorry, I think the "source::^" in your regex may be the problem. The "^" is saying "at the start of the string", but that isn't true in this case. Remove the "source::" and you should be ok.

Dave

View solution in original post

dshpritz
SplunkTrust
SplunkTrust

Sorry, I think the "source::^" in your regex may be the problem. The "^" is saying "at the start of the string", but that isn't true in this case. Remove the "source::" and you should be ok.

Dave

carmackd
Communicator

thanks! good catch, that worked, but i removed the "^". If i remove the "source::" the new host name appears as "host=source::myapphost"

0 Karma

dshpritz
SplunkTrust
SplunkTrust

The regex looks right to me. What is in your props.conf?

Dave

0 Karma

carmackd
Communicator

[inhouseapp]

BREAK_ONLY_BEFORE_DATE = false

BREAK_ONLY_BEFORE = <\w+\s\d+,\s[0-9]{4}\s\S+\s\w+\s\w+>

TRANSFORMS-override = inhouseapp_override_host

I don't have the option to mark as code so the regex in BREAK_ONLY_BEFORE is coming through funny.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...