Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Append Domain name at index time?

$
0
0
All, I have logs coming in from /var/log/messages and /var/log/maillog which have the hostname not the FQDN. There is just too much change control and politics to get them fixed at the source. Looking for a way at index time to just make the correction. Server names are well formed 12 characters ending in three numbers. So I need to create a props.conf/transforms.conf on my indexer, just not sure what it will look like. If host = .*\n\n\n then append mycompany.com Any ideas what that might look like?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>