Getting Data In

How do I route based on host and source type?

lukessi
Path Finder

Hi,

I am routing traffic to a 3rd party. I have done some of this based on a host and others based on the source type.

But I now need to route based on a host and a sourcetype and I can't work out how to do it?

Any tips of where to look?

0 Karma
1 Solution

FrankVl
Ultra Champion

I think you could do something along these lines, triggering the transforms based on sourcetype, but inside the transforms config filter by host using the REGEX.

props.conf:

[yoursourcetype]
TRANSFORMS-setrouting = your-routing

transforms.conf

[your-routing]
SOURCE_KEY = MetaData:Host
REGEX = (host1|host2|...|hostn)
DEST_KEY = _TCP_ROUTING
FORMAT = your-outputgroup

View solution in original post

FrankVl
Ultra Champion

I think you could do something along these lines, triggering the transforms based on sourcetype, but inside the transforms config filter by host using the REGEX.

props.conf:

[yoursourcetype]
TRANSFORMS-setrouting = your-routing

transforms.conf

[your-routing]
SOURCE_KEY = MetaData:Host
REGEX = (host1|host2|...|hostn)
DEST_KEY = _TCP_ROUTING
FORMAT = your-outputgroup

krithikar
Engager

What if we have multiple hosts , say 500 and above can we mark and * to pick up all the host name .

REGEX = (host*)

If my host name starts with ABCD and if i say ABCD* will this work ?. Or say my events have these hosts under a field called computername 

REGEX = (?ms)(ComputerName=ABCD*.domain.com)

Tags (1)
0 Karma

lukessi
Path Finder

Cheers mate I came to that solution too. Just double checking if there was another way.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...