Hi,
I am doing a lookup for classifying the "location" of servers using host-name using props.conf. But when i am doing the search i am getting the location fields more than once for a each event. Hence when I count for the events by location, i am getting always twice the actual count.
Props.conf
[cds_cdsmpoll]
LOOKUP-cds_cdsmpoll = cds_address hostname OUTPUT location as LOCATION
Has any one seen this behaviour before ?
Do you have the hostname field showing more than once within an event? E.g. somewhere there is an alias to change host to hostname as well as a field extraction for hostname within the event. This would result in the location field being produced twice.
Also I haven't tested this but maaybe its possible its because you are changing the name to an upper case version. Have you tested it without the as LOCATION
? This is just a rename function, it should work without the final as
conversion.