Splunk Search

Host regex stopped working after upgrade

Communicator

I recently upgraded a forwarder from 4.0.9 to 4.1.4, and after I did so, the host_regex I had in place on 4.0.9 stopped working. Does anyone know why it would work with 4.0.9, and not 4.1.4? Here is the host regex attribute I'm using, and an example of the file path.

host_regex = ^\/\w+\/\w+\/\w+\/\w+\/(\w+)

/mount/u01/vault/win/hostname.xxxx.xxxx.com/hostname.xxxx.xxxx.com-syslog-info-2011-01-08

Tags (2)

Splunk Employee
Splunk Employee

It would be helpful to post your full inputs.conf stanza, plus any props that are relevant to the input.

0 Karma