Getting Data In

Storing the correct host dimension with mcollect

JustinSC
Explorer

I've got some events I'm converting to metrics using mcollect with a scheduled report. Does anyone know how to get the metrics to store the original host from the logs instead of whichever indexer they get sent to?

This is the query I'm using to populate the metrics:

 

sourcetype=mysourcetype host=* "Events to count"
| bin _time span=1m
| stats count AS _value BY _time, host
| eval metric_name="My.Metric.Name"
| mcollect index="prod_metrics"

 

The host field in the metrics ends up being a random indexer from our cluster. I know I could always rename host as server, but if possible I'd like to use the expected field name since all our other natively populated metrics are by host.

Tags (1)

andreasz
Path Finder

Same problem her.
Tried everything:

host=host

host=$host$

host={host}

...

 

 

0 Karma

JustinSC
Explorer

I never came up with a solution. I stopped using mcollect and now use the Summary Indexing feature with Metrics index type, which I believe requires Splunk 8.1.

For some reason I never setup any metrics to use a host dimension, but perhaps this feature preserves it. I believe something like this would work, or at least it's worth a shot:

sourcetype=mysourcetype host=* "Events to count"
| timechart limit=0 span=1m count by host
| untable _time host "My.Metric.Name"

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...