Splunk Enterprise

Original_host

Kiko
Observer

Original_host Filed extraction should be aligned if a Syslog server have different date/time format. The current filed extraction is defined based on your syslog server and I am positive that this app works only for a couple of Splunk customers.

Labels (1)
Tags (1)
0 Karma

Kiko
Observer

in the props.conf, the original_host extraction won't work for the majority of users  - EXTRACT-original_host = \d+-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d+[\+\-]\d{2}:\d{2}\s(?<original_host>\S+)

original_host is I believe a crucial fiield, so all datamodels can work as expected

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Ok. We have no context. You're writing as if we were supposed to know what you are talking about. You're posting in a Splunk Enterprise section of this forum, which is meant for questions specific to on-premise software functionality and issues. But you selected a specific add-on as a product you're referring to. In such case you should have posted in the 'All Apps and Add-ons' section. We do not have glass orbs and don't know what you mean 😉

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Honestly? I have no idea what you're talking about. Could you be more specific?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...