In the filter expression window (when performing data captures), how would I filter for hosts that have DHCP anywhere in the hostname?

The equivalent to running host= * DHCP * in Splunk.

IF the data contains a host field, you can use the match method:


If the host name is in the _raw string, sub _raw for host in the above.

