hi i have lot's of log file that start with this line for each log
********** LOGFILE FOR SERVER 'host22', AT THE DAY OF : 2020/04/25 **********
now how can i set host name for each log,
expected host name: host22
FYI: all log files copy manually from each server daily, and not use forwarder in this scenario.
all loge copy in /opt like below, and splunk continuously index this path:
log1
log2
log3
...
any recommendation?
Thanks
transforms.conf
try INGEST_EVAL
or DEST_KEY = MetaData:Host
You mean i should use something like this?
Override host:
[hostoverride]
DEST_KEY = MetaData:Host
REGEX = ^[^'\n]*'(?P\w+)
FORMAT = host::$1
yes, Don't forget props.conf.