My events have a field like this:
I would like to leave the default host field that splunk assigns, but take the host field from the event and rename it to something like event_host.
How would do I do that?
Probalby the easiest way to do this would be to use the interactive field extractor. You can bring it up by clicking on the green arrow to the left of the event and select "extract fields".
This is a short video that demonstrates the usage:
If this doesn't work then we can try some other options....
View solution in original post
That worked great, thanks for the help.