Splunk Enterprise

How To Append Nix Variable to MetaData:Source

morethanyell
Contributor

Hi,

How to properly append the server's hostname, i.e. $HOSTNAME to the source? This was my failed attempt:

 

 

#transforms.conf

[append-hf-hostname-to-src]
SOURCE_KEY = source
REGEX = (.*)
FORMAT = source::$1:$HOSTNAME
DEST_KEY = MetaData:Source

#props.conf

[my:cute:sourcetype]
TRANSFORMS-newsrc=append-hf-hostname-to-src

 

 

 

Thanks in advance.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

From what I understand, the only environment variable you can rely on in config file is $SPLUNK_HOME.

---
If this reply helps you, an upvote would be appreciated.
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!