Rewriting sourceHost automatically



  • Avatar
    Latimer Luis

    Jon - would it be safe to assume that the _sourceHost would be equivalent to the _collector name in this case? 

    If so, you can configure a Field Extraction Rule (FER) with this parse expression:

    _collector as _sourceHost

    The tricky thing could be what metadata you would need to use to limit the search scope for this FER. Maybe something like the following would work: 

    _sourceHost=*<domain1>.com or _sourceHost=*<domain2>.com

  • Avatar

    Yes, in this case  _sourceHost would be equivalent to the _collector name.


Please sign in to leave a comment.