Getting Data In

Can I Assign to Host The Value From A Variable?

attoriozi
Explorer

I would like to assign to "host" a variable initiated in the input script.

For instance, is it possible something like this:

[script://./bin/hostrandom.sh]

interval = 10

host = $RHOST

sourcetype = hostrandom

disabled = 0

where

cat ../bin/hostrandom.sh

export RHOST=HOST$RANDOM

echo "This is the Event for $RHOST "

Tags (2)

gkanapathy
Splunk Employee
Splunk Employee

You can't do this based on a value that is set in the scripted input, though you can use a variable that is set in the environment in which the Splunk process runs. However, if you have a scripted input, there are other ways to set the host by having the script itself output a field that can be transformed at index time, or by using dynamic metadata assignment

gkanapathy
Splunk Employee
Splunk Employee

Don't use should_linemerge = true. Use SHOULD_LINEMERGE = false and a unique LINE_BREAKER pattern between events.

0 Karma

attoriozi
Explorer

still not good: in my case the input script generates an event that needs to be split in multiple events (SHOULD_LINEMERGE=true). In this case only one of those events is going to be associated to the extracted host, all the other are going to be associated to default host.

0 Karma

attoriozi
Explorer

basically doing the above and then use a index time extraction. Ok thanks

0 Karma

attoriozi
Explorer

Documentation is not very clear. I think it just suggests a script like: << echo "This is the Event for host=RHOST$RANDOM " >>

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...