<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Splunk syslog Server in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271825#M31546</link>
    <description>&lt;P&gt;I think this might solve your problem. In inputs.conf for this input, set &lt;BR /&gt;
connection_host=ip&lt;BR /&gt;
Are you sure the data coming in has ip address and not hostnames in the events ?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2016 14:38:37 GMT</pubDate>
    <dc:creator>sshelly_splunk</dc:creator>
    <dc:date>2016-10-25T14:38:37Z</dc:date>
    <item>
      <title>Configuring Splunk syslog Server- Where to find the server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271824#M31545</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;
&lt;P&gt;Anyone knows where to find the syslog server configuration for Splunk ?&lt;/P&gt;
&lt;P&gt;I need to change the fields that are added by splunk when it receives the data. I am getting the timestamp+hostname added by the syslogd but instead i need to add timestamp+IP. I am currently using UDP syslog. I tried modifying the "host" and "connection_host" in the inputs.conf but nothing seems to change I keep getting the VIP name as hostname. The indexer is currently receiving on port 514 and it is a windows server.&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 15:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271824#M31545</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2022-06-21T15:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271825#M31546</link>
      <description>&lt;P&gt;I think this might solve your problem. In inputs.conf for this input, set &lt;BR /&gt;
connection_host=ip&lt;BR /&gt;
Are you sure the data coming in has ip address and not hostnames in the events ?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 14:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271825#M31546</guid>
      <dc:creator>sshelly_splunk</dc:creator>
      <dc:date>2016-10-25T14:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271826#M31547</link>
      <description>&lt;P&gt;Hello sshelly, &lt;BR /&gt;
Thank you for your reply.&lt;BR /&gt;
I am using UDP and connection_host is a TCP parameter.  Also I tried changing the "host" field in the input and setting it to random values and it wasn't taken into consideration by splunk..&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 15:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271826#M31547</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2016-10-25T15:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271827#M31548</link>
      <description>&lt;P&gt;David - I checked input.conf spec, and if you go down to look at UDP section, connection_host is there as well as an option. Can u possibly share your current inputs.conf ?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 17:04:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271827#M31548</guid>
      <dc:creator>sshelly_splunk</dc:creator>
      <dc:date>2016-10-25T17:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271828#M31549</link>
      <description>&lt;P&gt;As per sshelly's comment connection_host should fix your issue. If you want more flexibility you might consider something like syslogNG, I have provided an example &lt;A href="https://answers.splunk.com/answers/451674/how-do-i-use-syslogng-to-replace-splunk-tcp-or-udp.html"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 01:08:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271828#M31549</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2016-10-26T01:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271829#M31550</link>
      <description>&lt;P&gt;None of this is working..My questions is about syslog config file in splunk, like the "syslog.conf" file on linux.. I want to find the root configuration for the syslog that splunk is running. .&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 08:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271829#M31550</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2016-10-26T08:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271830#M31551</link>
      <description>&lt;P&gt;There isn't any syslog.conf file in Splunk. I think Splunk starts  a process which runs on specific port for tcp/udp connection. &lt;/P&gt;

&lt;P&gt;In addition to what others have suggested, we have used props /transforms to selectively update index/source type depending on specific condition. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    Props.conf 
    [syslog]
    TRANSFORMS-feye = fytest


    transforms.conf
    [fytest]
    REGEX = 10\.35\.136\.91|10\.35\.136\.90|10\.39\.132\.68
    REGEX = 10.35.136.9[01]|10.35.136.89|10.39.132.6[89]|10.39.132.70
    DEST_KEY=_MetaData:Index
    FORMAT=abc
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 26 Oct 2016 08:56:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271830#M31551</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2016-10-26T08:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271831#M31552</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;/P&gt;

&lt;P&gt;This took me a while to figure out and I couldn't find it documented beside in a comment on anwser &lt;A href="https://answers.splunk.com/answers/153831/cannot-change-host-field-in-syslog-data.html" target="_blank"&gt;https://answers.splunk.com/answers/153831/cannot-change-host-field-in-syslog-data.html&lt;/A&gt;  (if anyone does find the doc for it please link it here)...&lt;BR /&gt;
When the sourcetype &lt;CODE&gt;syslog&lt;/CODE&gt;is used the &lt;CODE&gt;host&lt;/CODE&gt; field value is extracted automatically from the data regardless of what is configured as host or connection_host in the input.conf. &lt;CODE&gt;syslog&lt;/CODE&gt; sourcetype takes the value that is right after the date in the message and considers it the host.&lt;BR /&gt;
The solution was simply to use a different sourcetype name for the udp input and then apply the &lt;CODE&gt;connection_host=ip&lt;/CODE&gt; configuration&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:33:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271831#M31552</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2020-09-29T11:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271832#M31553</link>
      <description>&lt;P&gt;I am sorry. I didn't think of the "default" syslog sourcetype (as garethatiag pointed out). I would copy/paste the syslog sourcetype (found in $SPLUNK_HOME/etc/system/default/props.conf, and paste into $SPLUNK_HOME/etc/system/local/props.conf the following. You may need to "play" with it a bit, but I think that should suffice. &lt;/P&gt;

&lt;P&gt;[mynewsyslog]&lt;BR /&gt;
pulldown_type = true&lt;BR /&gt;
maxDist = 3&lt;BR /&gt;
TIME_FORMAT = %b %d %H:%M:%S&lt;BR /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 32&lt;/P&gt;

&lt;H2&gt;remove following line&lt;/H2&gt;

&lt;P&gt;TRANSFORMS = syslog-host &lt;/P&gt;

&lt;H2&gt;insert following line&lt;/H2&gt;

&lt;P&gt;connection_host = ip&lt;BR /&gt;
REPORT-syslog = syslog-extractions&lt;BR /&gt;
SHOULD_LINEMERGE = False&lt;BR /&gt;
category = Operating System&lt;BR /&gt;
description = Mysyslog sourcetype to accomadate ip for host as opposed to hostname for host&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271832#M31553</guid>
      <dc:creator>sshelly_splunk</dc:creator>
      <dc:date>2020-09-29T11:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271833#M31554</link>
      <description>&lt;P&gt;dude don't say you're sorry lol you rock, thank you very much for your help &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 13:10:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/271833#M31554</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2016-10-26T13:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk syslog Server</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/602357#M77040</link>
      <description>&lt;P&gt;template (name="trendmicro" type="string" string="/PROD/trendmicro/%fromhost-ip%/trendmicro.log")&lt;BR /&gt;template (name="asa" type="string" string="/PROD/asa/%fromhost-ip%/asa.log")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ruleset(name="remote-udp"){&lt;BR /&gt;if $fromhost-ip == '10.100.' then { action(type="omfile" dynafile="trendmicro") }&lt;BR /&gt;if $fromhost-ip == '10.0.4' then { action(type="omfile" dynafile="trendmicro") }&lt;BR /&gt;if $fromhost-ip == '10.135.' or $fromhost-ip == '10.0.' then { action(type="omfile" dynafile="asa") }&lt;BR /&gt;if $fromhost-ip=='10.19' or $fromhost-ip == '10.19' then { action(type="omfile" dynafile="fireeye") }&lt;/P&gt;&lt;P&gt;stop&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# bind ruleset to tcp listener and activate it:&lt;BR /&gt;input(type="imudp" port="514" ruleset="remote-udp")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;template (name="rsyslog-fmt" type="string"&lt;BR /&gt;string="%TIMESTAMP% %HOSTNAME% %syslogtag%%msg:::sp-if-no-1st-sp%%msg:::drop-last-lf%\n"&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;template (name="Checkpoint" type="string" string="/var/log/splunk/Checkpoint/%HOSTNAME%/checkpoint.log")&lt;/P&gt;&lt;P&gt;template (name="Checkpoint_sys" type="string" string="/var/log/splunk/Checkpoint_sys/%HOSTNAME%/checkpoint.log")&lt;/P&gt;&lt;P&gt;template (name="F5" type="string" string="/var/log/splunk/F5/%HOSTNAME%/f5_waf.log")&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ruleset (name="network-logs") {&lt;BR /&gt;#if $HOSTNAME startswith "SCMD-SPL-DEPS" then { action (type="omfile" dynafile="test" template="rsyslog-fmt") stop }&lt;/P&gt;&lt;P&gt;#if $fromhost-ip=="10.40.71" then { action (type="omfile" dynafile="test" template="rsyslog-fmt") stop }&lt;/P&gt;&lt;P&gt;action (type="omfile" file="/var/log/splunk/uncategorised.log" template="rsyslog-fmt-unc") stop&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#input (type="imtcp" port="514" ruleset="network-logs")&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 03:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-Splunk-syslog-Server-Where-to-find-the-server/m-p/602357#M77040</guid>
      <dc:creator>nagarjunay</dc:creator>
      <dc:date>2022-06-20T03:59:49Z</dc:date>
    </item>
  </channel>
</rss>

