I need some help building regex for host_regex.
Please and thank you!
/opt/splunk/SFTP/SYSTEM/daftm44de_sec.14-08-29.log
/opt/splunk/SFTP/SYSTEM/opd1_sys.14-08-27.log
/opt/splunk/SFTP/SYSTEM/opd9_sys.14-12-29
The host name is, for example:
oppd1_sys
daftme44de_sec
oppd9_sys
Hi omgwut56k,
based on the provided data, try this as regex:
\/([\w\d]+)\.
hope this helps ...
cheers, MuS