I'd like to set at search_time a new field, with a value according to the host :
if host=abc.com then
elseif host=bbb.com then
Is it possible to make if statement in the inline field of the transformation ? How do it would look like ?
I believe using tags would be ideal in this case.
http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Tagthehostfield
I believe using tags would be ideal in this case.
http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Tagthehostfield
Thanks, it is what I was searching for.
But I couldn't find the way how to print the tag-name in the result ? By default the hostname is printed... ?