Getting Data In

Storing the correct host dimension with mcollect

JustinSC
Loves-to-Learn

I've got some events I'm converting to metrics using mcollect with a scheduled report. Does anyone know how to get the metrics to store the original host from the logs instead of whichever indexer they get sent to?

This is the query I'm using to populate the metrics:

 

sourcetype=mysourcetype host=* "Events to count"
| bin _time span=1m
| stats count AS _value BY _time, host
| eval metric_name="My.Metric.Name"
| mcollect index="prod_metrics"

 

The host field in the metrics ends up being a random indexer from our cluster. I know I could always rename host as server, but if possible I'd like to use the expected field name since all our other natively populated metrics are by host.

Labels (1)
Tags (1)
0 Karma