Getting Data In
Highlighted

Host name can not be change

Explorer

Hi all,

I am new to splunk, I want a directory name as Host name my directory structure is as follows:

C:/Program Files/Splunk/etc/apps/ntt_tougou/tougou_logs/AB/abcd/log1.csv
C:/Program Files/Splunk/etc/apps/ntt_tougou/tougou_logs/FS/kfcd/log1.csv
C:/Program Files/Splunk/etc/apps/ntt_tougou/tougou_logs/AVD/gbd/log1.csv

I want different host name like directory names AB FS AVD

input.conf:
[monitor:C:/Program Files/Splunk/etc/apps/ntt_tougou/tougou_logs/]
host_segment =7

By above configuration I am getting host name as default name of my computer. Is my settings are correct ? Where I am wrong ?

Your help will be appreciated.

Tags (1)
0 Karma
Highlighted

Re: Host name can not be change

Builder

Is your file named 'input.conf' or 'inputs.conf'?

0 Karma
Highlighted

Re: Host name can not be change

Communicator

The only time we've used host_segment, the segment name is in the monitor stanza (rather than after it somewhere), and it has worked well for us.

ie:

Instead of -

C:/Program Files/Splunk/etc/apps/ntt_tougou/tougou_logs

Try something like -

C:/Program Files/Splunk/etc/apps/ntt_tougou/tougou_logs/.../.../*

I have no idea if that will help, but it is worth a try until someone with a more definitive answer can chime in...

View solution in original post

0 Karma
Highlighted

Re: Host name can not be change

Explorer

Thank you very much for the help....
Its working..!!!!

0 Karma
Highlighted

Re: Host name can not be change

Explorer

it is inputs.conf sorry for spell mistake.

0 Karma