Splunk Search

Why does SOURCE_KEY=MetaData:Host not work for REPORT stanzas?

Jason
Motivator

I am trying to extract data from the Host field at search time, using a REPORT- in props.conf.

The extraction works when I use SOURCE_KEY = ComputerName, a field in the data that contains the host. But, this is only available in WinEventLog data, and I want it to apply to all hosts regardless of type of data.

I have tried SOURCE_KEY = MetaData:Host, but it does not work. What gives?

0 Karma
1 Solution

Jason
Motivator

It seems that MetaData:Host is only available at index time, for index-time transforms.

Use SOURCE_KEY = host when using the transform at search time.

View solution in original post

Jason
Motivator

It seems that MetaData:Host is only available at index time, for index-time transforms.

Use SOURCE_KEY = host when using the transform at search time.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...