Splunk Search
Highlighted

Can you help me build a regex that would parse %host% from the following log directories?

Engager

I am trying to use host_regex in input.conf
I have log directories as,

/var/log/rsyslog/%year%/%month%/%date%/%host%/syslog

$host$ can be any of following three,
abc-i-1234adfd-foo1 
xx.xx.xx.xx
ip-xx-xx-xx-xx.ec2.internal

thanks,

0 Karma
Highlighted

Re: Can you help me build a regex that would parse %host% from the following log directories?

Contributor

Hey,

I think the easiesst way is if you use host_segment.

For you this would be
host_segment = 7

See: https://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf

If set to N, Splunk software sets the Nth "/"-separated segment of the path as 'host'.
For example, if host_segment=3, the third segment is used.

Cheerz,
Björn

Highlighted

Re: Can you help me build a regex that would parse %host% from the following log directories?

Engager

I tried that. it's working only with following 2 %host% values
abc-i-1234adfd-foo1
ip-xx-xx-xx-xx.ec2.internal

it's not able to extract 3rd value which is xx.xx.xx.xx (IP)

0 Karma
Highlighted

Re: Can you help me build a regex that would parse %host% from the following log directories?

Engager

I tried host_segment = 7. I was actually using that. It was working fine until I had %host% = ip-xx-xx-xx-xx.ec2.internal or abc-i-1234adfd-foo1 .

now, I got this new condition where I am getting ip (XX.XX.XX.XX) in %host%. in this specific case, splunk forwarder is not able to extract IP from that field and it's sending logs with default host (splunk forwarder's hostname) field.

as it's not working, I want to try out host_regex and see if that works.

0 Karma
Highlighted

Re: Can you help me build a regex that would parse %host% from the following log directories?

Builder

try any one of this in your inputs.conf for host_regex, it helps if you can post the year/month/data format as well to test the regex...

host_regex = /var/log/rsyslog/\d+/\d+\/\d+/([\w\d\\.-]+)\/syslog
host_regex = \/var\/log\/rsyslog\/\d+\/\d+\/\d+\/([\w\d\\.-]+)\/syslog

lookup this Splunk doc..

http://docs.splunk.com/Documentation/Splunk/7.2.1/Data/Setadefaulthostforaninput#Settheeventhostwiththehostregexattribute

0 Karma