Hi, I have a UNIX server Solaris 8 that ac/behave like a Splunk Proxy server for 2 other UNIX servers Solaris 8. In other words the 2 Solaris servers send the syslog file to the UNIX Solaris Proxy server. I am trying to create a query that will shows the events coming from the 2 UNIX Solaris 8 servers. I run the below query for example: index=nix* serverproxy* | eval Status=if(like(source, "%FirstUNIXSolaris8%"), 1, 0) I am not getting any event that will show the FirstUNIX Solaris8 name/hostname. Please any suggestion how to create the specific query ? Thanks, Regards. Roberto
... View more