Hi guys,
I've tried several transformations and even field extractor but I can't get Splunk to extract the hostname out of Kiwi's syslog files.
I have created the following transformation: (?i)^[^.]*.\w+\t(?P
I even created a new sourcetype with no luck.
Any ideas would be appreciated.
Thank you
Being a New Zealander , I feel compelled to answer 🙂
For the "host" field , you might want to consider performing an index time transform (via entrys in props.conf and transforms.conf)
props.conf
[kiwisourcetype]
TRANSFORMS-host=extract-kiwi-host
transforms.conf
[extract-kiwi-host]
DEST_KEY = MetaData:Host
REGEX = (?i)^[^.]*.w+t([^t]+)
FORMAT = host::$1
Can you also post an example from the syslog file so I can check the accuracy of your regex ?