I have a feed that has nice key-value pair fields, which are automatically getting populated, via KV_MODE=auto in my props.conf. My question is what is the best way to automatically map one of these fields to the host field in the event.
Hope you are looking for automatic field lookup.
http://docs.splunk.com/Documentation/Splunk/6.1.3/Knowledge/Usefieldlookupstoaddinformationtoyoureve...
Hi-
Take a look at this doc, that should answer your question: http://docs.splunk.com/Documentation/Splunk/6.1.3/Data/Overridedefaulthostassignments
Although you will have to specify a regex and not depend on the KV_MODE extraction of the host name.