March 2018
Beginner to intermediate
576 pages
13h 29m
English
If your hostnames are appearing differently from different sources, for instance, syslog versus Splunk forwarders, you can use a transform to normalize these values. Given our hostname, vlbmba.local, we may want to only keep the portion to the left of the first period. The stanza would look like this:
[normalize_host] SOURCE_KEY = MetaData:Host DEST_KEY = MetaData:Host REGEX = (.*?). FORMAT = host::$1
This will replace our hostname with vlbmba. Note these two things:
Read now
Unlock full access