Security

How to obtain hostname/eventtype from file name

pedroborges
New Member

Hi,

I'm currently evaluating Splunk (just trying out the free version), and have a question regarding the way Splunk determines the host a given event belongs to, and the event's type.

The way the logging system (I was assigned to) is currently implemented is that logs get compressed on the clients and then SSH'd to the log server. There is audit log software that handles all of it, but I'm looking to possibly replacing it. Anyway, I tried pointing Splunk to the compressed files and it indeed looks inside and indexes it (I was impressed). However, it seems to be a bit off when it comes to figuring out the logtype and hostname for the events. Both of these pieces of information are contained in the compressed file's filename where the logs are actually located. Is there a way to tell Splunk to use those values for any and all events it finds in a particular (compressed) log file?

The file names have the format: ...gz

Thanks!
Pedro

Tags (1)
0 Karma

jeff
Contributor

see the host_regex under [monitor://<path>] in http://docs.splunk.com/Documentation/Splunk/5.0.2/admin/Inputsconf

0 Karma

pedroborges
New Member

I found my answer after doing a simple google search. I should do that before posting next time. >.< Thanks!

http://docs.splunk.com/Documentation/Splunk/latest/Data/setadefaulthostforaninput#Dynamically_set_th...

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...