Getting Data In

How to add constant to HOST name using regular expression

neilli
Engager

I am using a reg-exp to set the host name from the file path
e.g. \servername\logs\application\ag_clientname_log
monitor \servername\logs\application\ag_*
host_regex = (ag_[^_]+)
this gives me "ag_clientname" but I want "clientname_ag_logs" to match what we had previously been collecting.

0 Karma

woodcock
Esteemed Legend

There is no way to do this that I know. I would create a link to each file in a different directory and give each the link the correct name and point the monitor to the other directory. This consumes NO extra disk space (only 1 inode per file).

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi
You could use also eval
| eval host=substr(host,4,15)+"_ag_logs"

Bye
Giuseppe

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...