Splunk Search

How to replace hostnames with own names

svalivarthey
New Member

When i use below query i can see multiple servers in the index.

Index=abc  sourcetype=vmstat (host=windows1* OR  host=windows2* OR host=windows3*) | eval cpu_percent_util=(100-pctIdle) | timechart span=1m avg(cpu_percent_util) by host

i can see graph by windows1, windows2, windows 3 but i want to see the host names like Web1, Web2, Web 3

Please help me on this.

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need a way to map from one name to another - how do you know whether windows1 is Web1 or Web2? Is this mapping stored in a lookup somewhere, do you include it in a case statement in the search, can you get it through a join with another search?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...