Knowledge Management

props.conf: stanza "host::...." using regex

ktn01
Path Finder

Hello,

The documentation says that a stanza [host::<host>] in "props.conf" must be used with a host-pattern

Is it a way to use a regexp?

I have to match host names like "[vp][mnas][pdtiv].*"

Labels (1)
0 Karma
1 Solution

somesoni2
Revered Legend

Reference: https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Propsconf#GLOBAL_SETTINGS

 The stanza name with "host:..." and "source:..." uses PCRE (Perl-compatible regular expressions).

syntax:
... recurses through directories until the match is met
    or equivalently, matches any number of characters.
*   matches anything but the path separator 0 or more times.
    The path separator is '/' on unix, or '\' on Windows.
    Intended to match a partial or complete directory or filename.
|   is equivalent to 'or'
( ) are used to limit scope of |.
\\ = matches a literal backslash '\'.

 

You can use something like this

[host::(v|p)(m|n|a|s)(p|d|t|i|v)*]

View solution in original post

0 Karma

somesoni2
Revered Legend

Reference: https://docs.splunk.com/Documentation/Splunk/8.2.2/Admin/Propsconf#GLOBAL_SETTINGS

 The stanza name with "host:..." and "source:..." uses PCRE (Perl-compatible regular expressions).

syntax:
... recurses through directories until the match is met
    or equivalently, matches any number of characters.
*   matches anything but the path separator 0 or more times.
    The path separator is '/' on unix, or '\' on Windows.
    Intended to match a partial or complete directory or filename.
|   is equivalent to 'or'
( ) are used to limit scope of |.
\\ = matches a literal backslash '\'.

 

You can use something like this

[host::(v|p)(m|n|a|s)(p|d|t|i|v)*]
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...