To me this should be simple, but I can't get it. When entering host info while adding data I select "regex on path" and enter the regex for my capture group, but it still returns my default host upon search for that particular source. Even if I change my default host name in system/local or search/local inputs.conf, I still get my default host. Also if I select "segment on path" and just try to name it something along the path, I still get my default host. Even if my regex was not sound, some of these other options should work, where is Splunk continually pulling my default host from if I take it out of .conf files entirely?
... View more