Getting Data In

Setting host to hostname vs IP address

agodoy
Communicator

I have different devices sending data via syslog.

Current Stanza Example:

[udp//IP:PORT]
host = hostname
sourcetype = syslog

However, events still show up as host = ip address. Is there another place to do this?

Tags (2)
0 Karma

agodoy
Communicator

It seems that the process is not as straight forward as I thought for syslog devices.

See this blog post:

http://blogs.splunk.com/2008/04/16/overriding-default-syslog-host-extraction/

Now trying to figure out how to do this in a Cluster.

0 Karma

gnovak
Builder

I had the same problem, even if I told it not to. It sorta double dips your hostnames, especially if you already had the hostname show up prior to enabling syslog.

0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...