Getting Data In

What is the best way to automatically map a field extracted via KV_MODE=auto to the host field in the event?

a212830
Champion

I have a feed that has nice key-value pair fields, which are automatically getting populated, via KV_MODE=auto in my props.conf. My question is what is the best way to automatically map one of these fields to the host field in the event.

0 Karma

neelamssantosh
Contributor
0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

Hi-

Take a look at this doc, that should answer your question: http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Overridedefaulthostassignments

Although you will have to specify a regex and not depend on the KV_MODE extraction of the host name.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...