Getting Data In

How do I fix my host_regex in order to extract the hostname from my log file?

edwardrose
Contributor

Hello all

I am extremely terrible with regex and frankly I am stumped. I am trying to get hostname from the log file that is generated in the path.

/var/log2/collab/bitdefender/ies-av-web-01.log
/var/log2/colab/bitdefender/wv-av-web-01.log

I used the following thinking it would work

[monitor:///var/log2/collab/bitdefender/*.log]
host_regex = [^.log]

But it didn't and the examples from other questions people are specifying the entire path in the host_regex, which from what I read isn't necessary since it should be reading the entire path from the monitor stanza.

thanks in advance

0 Karma
1 Solution

sundareshr
Legend

Try this for your host_regex

host_regex=bitdefender\/(.*)\.log

View solution in original post

sundareshr
Legend

Try this for your host_regex

host_regex=bitdefender\/(.*)\.log
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...