Splunk Search

Extracting host from host segment doesn't work

mmohiuddin1512
Explorer

Hi :

I have a monitoring stanza which splunk process is monitoring logs from:

/var/log/hosts//Tue/-2017050209

This is what I have defined in inputs.conf:

[monitor:///var/log/hosts/56.*/.../(\d+).(\d+).(\d+).(\d+)-(\d+)]
host_segment = 4
sourcetype = syslog
index = networkperimeter_firewalls
source = ASA-casyslog1_server
blacklist = .(gz|bz2|z|zip)$
ignoreOlderThan = 1d
crcSalt =

But while checking the logs on Splunk Search Head, the host value shows the host where the UF is installed, it is not monitoring the host from host_segment value, is there something I am missing, or doing incorrect.

Your inputs are highly appreciated.

Tags (2)
0 Karma

koshyk
Super Champion

I feel , the reason is because you have mentioned sourcetype as "syslog" and it will use the inbuilt syslog-host transform
Can you just try

[monitor:///var/log/hosts/56.*/.../(\d+).(\d+).(\d+).(\d+)-(\d+)]
host_segment = 4
sourcetype = mydummy
index = networkperimeter_firewalls
source = ASA-casyslog1_server
blacklist = .(gz|bz2|z|zip)$
ignoreOlderThan = 1d

if This is successful, we will then think of how to override the sourcetype to use host_segment

0 Karma

xavierashe
Contributor

What part of that directory is the hostname?

0 Karma

xavierashe
Contributor

So did you delete the hostname? So is it this?

/var/log/hosts/HOSTNAME/Tue/-2017050209

Have you tried this:

[monitor:///var/log/hosts/*/.../(\d+).(\d+).(\d+).(\d+)-(\d+)]
host_segment = 4
0 Karma

mmohiuddin1512
Explorer

4th segment

0 Karma

somesoni2
Revered Legend

It should work. This will only update the host for events coming from this monitor stanza, unless some setting is overriding it again at heavy forwarder/indexer level.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...