Hi
I have log file that copy on splunk server every day with below structure:
/data/appserver/ACC/20200617/log.customer1.20200617.bz2
/data/appserver/ACC/20200617/log.customer2.20200617.bz2
/data/appserver/ACC/20200617/log.cus1.20200617.bz2
/data/appserver/ACC/20200617/log.cus2.20200617.bz2
/data/appserver/ACC/20200617/log.cus3.20200617.bz2
now I want splunk consider everything between two dots as host name, like this:
customer1
customer2
cus1
cus2
cus3
I try to do this throgh web ui and "Set host" = "5" :
settings > datainputs > Files & Directories > /data/appserver/ACC/
is this correct? i mean splunk consider 5's part of address?
Thanks
first: you can't extract host name, I guess.
https://community.splunk.com/t5/Getting-Data-In/inputs-conf-segment-setting/td-p/346029
second: try TRANSFORMS stanza
https://community.splunk.com/t5/Archive/hostname-rename-using-TRANSFORMS/td-p/12009