Splunk Search

identify server host names as developemnt or test by name

Hudond
Path Finder

Good afternoon

I have a question about identifying the type of environment the servers are in by their hostnames being extracted using the Microsoft-add on for splunk.

The server hostnames are being indexed as follows:

servername"DV"

servername"TV"

Servername"DV"serverName

Servername"TV"servername

So server names that have the DV and TV designations are identified as belonging to the development and test environments. Sometimes the characters are at the end and sometimes they are in the middle of the server names.

I am looking at running a search that will identify the hostname as being in the development or test environments and adding that as a column to the search results fro the hostnames.

If the hostname does not have those designations I would like to identify them as "other"

I would appreciate any guidance of the best approach to use for the search string, that way I can research it and learn how to do it.

Thank you

Dan

 

 

 

 

Labels (1)
0 Karma
1 Solution

jwrjrobertson05
Explorer

You'll want to use eval with CASE something like...

 

index=<something> field=<whatever>
| eval ENV = CASE ( hostname LIKE "%DV%","DV", hostname LIKE "%TV%","TV",hostname LIKE "%","OTH")
| stats count by ENV

 

View solution in original post

jwrjrobertson05
Explorer

You'll want to use eval with CASE something like...

 

index=<something> field=<whatever>
| eval ENV = CASE ( hostname LIKE "%DV%","DV", hostname LIKE "%TV%","TV",hostname LIKE "%","OTH")
| stats count by ENV

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

If you are designing a Splunk forwarding architecture, it can be tempting to place a Universal Forwarder (UF) ...

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...