I trying to rename sourcetype for this regex but won't work
but when i remove the rename = httpd-access its work?
[access]
rename = httpd-access
EXTRACT-ip = [(?P
EXTRACT-host = (?i)^[^,]*,\d+\s+(?P
i using splunk Uforwarder
[monitor:///opt/log/*]
sourcetype = access
I am not sure I completely understand your question, but I am going to assume that your field extractions are not working when you have rename attribute set.
Sourcetype renaming is a search time operation that happens before field extractions. Thus Splunk will use search-time field extractions defined in [httpd-access] stanza for events that have been indexed as coming from the "access" sourcetype. Give the following props.conf stanzas (in the search head) a test run
[access]
rename = httpd-access
[httpd-access]
EXTRACT-ip = [(?P<ip>[^]]+)
EXTRACT-host = (?i)^[^,]*,d+s+(?P<host>[^ ]+)
I am not sure I completely understand your question, but I am going to assume that your field extractions are not working when you have rename attribute set.
Sourcetype renaming is a search time operation that happens before field extractions. Thus Splunk will use search-time field extractions defined in [httpd-access] stanza for events that have been indexed as coming from the "access" sourcetype. Give the following props.conf stanzas (in the search head) a test run
[access]
rename = httpd-access
[httpd-access]
EXTRACT-ip = [(?P<ip>[^]]+)
EXTRACT-host = (?i)^[^,]*,d+s+(?P<host>[^ ]+)
that work great help..! thank you very much.. FIXED!