Security

How to obtain hostname/eventtype from file name

pedroborges
New Member

Hi,

I'm currently evaluating Splunk (just trying out the free version), and have a question regarding the way Splunk determines the host a given event belongs to, and the event's type.

The way the logging system (I was assigned to) is currently implemented is that logs get compressed on the clients and then SSH'd to the log server. There is audit log software that handles all of it, but I'm looking to possibly replacing it. Anyway, I tried pointing Splunk to the compressed files and it indeed looks inside and indexes it (I was impressed). However, it seems to be a bit off when it comes to figuring out the logtype and hostname for the events. Both of these pieces of information are contained in the compressed file's filename where the logs are actually located. Is there a way to tell Splunk to use those values for any and all events it finds in a particular (compressed) log file?

The file names have the format: ...gz

Thanks!
Pedro

Tags (1)
0 Karma

jeff
Contributor

see the host_regex under [monitor://<path>] in http://docs.splunk.com/Documentation/Splunk/5.0.2/admin/Inputsconf

0 Karma

pedroborges
New Member

I found my answer after doing a simple google search. I should do that before posting next time. >.< Thanks!

http://docs.splunk.com/Documentation/Splunk/latest/Data/setadefaulthostforaninput#Dynamically_set_th...

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...