Hi,
How to properly append the server's hostname, i.e. $HOSTNAME to the source? This was my failed attempt:
#transforms.conf
[append-hf-hostname-to-src]
SOURCE_KEY = source
REGEX = (.*)
FORMAT = source::$1:$HOSTNAME
DEST_KEY = MetaData:Source
#props.conf
[my:cute:sourcetype]
TRANSFORMS-newsrc=append-hf-hostname-to-src
Thanks in advance.
From what I understand, the only environment variable you can rely on in config file is $SPLUNK_HOME.