Getting Data In
Highlighted

apache virtual hosts - custom field?

Contributor

I have several virtual hosts per Apache server, and I want to be able to report on them individually. I envision that I need to add a custom field, somehow, to each input for the indexer?

How could I achieve this? I would prefer all of this happen on the universalforwarder.

Thanks!

Tags (3)
0 Karma
Highlighted

Re: apache virtual hosts - custom field?

Splunk Employee
Splunk Employee

how is your log configured right now?

CustomLog ${APACHELOGDIR}/myvirtualhost/access.log

For example, if logs from a virtual host are organized under ${APACHELOGDIR}/myvirtualhost, you can add the following line to your input.conf

[monitor:///var/log/apache/myvirtualhost]
host_segment = 4

That way, "myvirtualhost" will be the host name for all log files that live under myvirtualhost.

Sorry If i misunderstood your question.

0 Karma
Highlighted

Re: apache virtual hosts - custom field?

Contributor

That could work, but I actually want to retain the host information as the server it comes from. It could be multiple servers.

0 Karma
Highlighted

Re: apache virtual hosts - custom field?

Splunk Employee
Splunk Employee

how about adding a field? you can add the following to your search:

| rex field=host /log/var/(?.*)/

you can also add it to your field extractor. Would this work?

Highlighted

Re: apache virtual hosts - custom field?

Contributor

Oh yeah, that makes a ton of sense! I'll see what I can do with that. Thanks!

0 Karma