<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using HTTP to get data into Splunk, but no host is set? - How do i set the host in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/555767#M6119</link>
    <description>&lt;P&gt;Hi -&lt;/P&gt;&lt;P&gt;We are using a hec /HTTP to send data (open telemetry)&amp;nbsp; into Splunk using an exporter -( exporter below)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/exporter/splunkhecexporter" target="_blank" rel="noopener"&gt;https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/exporter/splunkhecexporter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There does not seem a way to set host!&lt;BR /&gt;We can set "source" "source type" etc....but not host.&lt;/P&gt;&lt;P&gt;As a result, host = unknown.&lt;/P&gt;&lt;P&gt;When we try to set a host we get errors. Where do i define it?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="robertlynch2020_0-1623753585892.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14628i26AC35607C8EA211/image-size/medium?v=v2&amp;amp;px=400" role="button" title="robertlynch2020_0-1623753585892.png" alt="robertlynch2020_0-1623753585892.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="robertlynch2020_1-1623753602970.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14629i6D3126266A3F3EDA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="robertlynch2020_1-1623753602970.png" alt="robertlynch2020_1-1623753602970.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 10:40:18 GMT</pubDate>
    <dc:creator>robertlynch2020</dc:creator>
    <dc:date>2021-06-15T10:40:18Z</dc:date>
    <item>
      <title>Using HTTP to get data into Splunk, but no host is set? - How do i set the host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/555767#M6119</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;&lt;P&gt;We are using a hec /HTTP to send data (open telemetry)&amp;nbsp; into Splunk using an exporter -( exporter below)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/exporter/splunkhecexporter" target="_blank" rel="noopener"&gt;https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/exporter/splunkhecexporter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There does not seem a way to set host!&lt;BR /&gt;We can set "source" "source type" etc....but not host.&lt;/P&gt;&lt;P&gt;As a result, host = unknown.&lt;/P&gt;&lt;P&gt;When we try to set a host we get errors. Where do i define it?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="robertlynch2020_0-1623753585892.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14628i26AC35607C8EA211/image-size/medium?v=v2&amp;amp;px=400" role="button" title="robertlynch2020_0-1623753585892.png" alt="robertlynch2020_0-1623753585892.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="robertlynch2020_1-1623753602970.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14629i6D3126266A3F3EDA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="robertlynch2020_1-1623753602970.png" alt="robertlynch2020_1-1623753602970.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 10:40:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/555767#M6119</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2021-06-15T10:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Using HTTP to get data into Splunk, but no host is set? - How do i set the host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/555940#M6125</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can be solved from the exporter configuration.&lt;/P&gt;&lt;P&gt;We can see from below that we have set host.name - this will send the data as host to Splunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;This worded and thanks.&lt;/P&gt;&lt;P&gt;The file code is below.&lt;/P&gt;&lt;P&gt;receivers:&lt;BR /&gt;otlp: # pushed by clients&lt;BR /&gt;protocols:&lt;BR /&gt;grpc:&lt;BR /&gt;endpoint: :${OTLP_RECEIVER_PORT}&lt;/P&gt;&lt;P&gt;processors:&lt;BR /&gt;batch:&lt;BR /&gt;timeout: 1s&lt;BR /&gt;resource:&lt;BR /&gt;attributes:&lt;BR /&gt;key: host.name&lt;BR /&gt;value: "TEST1"&lt;BR /&gt;action: insert&lt;/P&gt;&lt;P&gt;exporters:&lt;BR /&gt;prometheus: # pulled by prometheus&lt;BR /&gt;endpoint: :${PROMETHEUS_EXPORTER_PORT}&lt;BR /&gt;splunk_hec: # pushed to splunk&lt;BR /&gt;token: "a04daf32-68b9-48b2-88a0-6ac53b3ec002"&lt;BR /&gt;endpoint: "&lt;A href="https://mx33456vm:8088/services/collector" rel="nofollow" target="_blank"&gt;https://mx33456vm:8088/services/collector&lt;/A&gt;"&lt;BR /&gt;source: "mx"&lt;BR /&gt;sourcetype: "otel"&lt;BR /&gt;index: "metrics_test"&lt;BR /&gt;insecure_skip_verify: true&lt;BR /&gt;splunk_hec/events: # pushed to splunk&lt;BR /&gt;token: "a04daf32-68b9-48b2-88a0-6ac53b3ec002"&lt;BR /&gt;endpoint: "&lt;A href="https://mx33456vm:8088/services/collector" rel="nofollow" target="_blank"&gt;https://mx33456vm:8088/services/collector&lt;/A&gt;"&lt;BR /&gt;source: "mx"&lt;BR /&gt;sourcetype: "otel"&lt;BR /&gt;index: "events_test"&lt;BR /&gt;insecure_skip_verify: true&lt;/P&gt;&lt;P&gt;service:&lt;BR /&gt;pipelines:&lt;BR /&gt;metrics:&lt;BR /&gt;receivers: [otlp]&lt;BR /&gt;processors: [batch,resource]&lt;BR /&gt;exporters: [prometheus,splunk_hec,splunk_hec/events]&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 09:28:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/555940#M6125</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2021-06-16T09:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Using HTTP to get data into Splunk, but no host is set? - How do i set the host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/571470#M10392</link>
      <description>&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;Need some inputs from you on implementing the open telemetry data in splunk, We wanted to do POC for our client and wanted to ingest open telemetry data logs and trace into splunk and I have following questions?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&amp;nbsp;Is it possible to do them in Splunk Enterprise trail license? Or Do we need to buy Splunk Observability module to monitor the open telemetry data?&lt;/LI&gt;&lt;LI&gt;Can we use universal forwarder to collect the logs and trace or do we need to have the&amp;nbsp;Splunk OpenTelemetry Connector?&lt;/LI&gt;&lt;LI&gt;Share the link or document to ingest the open telemetry data logs into splunk.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could you please guide me on this .&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 07:04:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/571470#M10392</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2021-10-19T07:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Using HTTP to get data into Splunk, but no host is set? - How do i set the host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/571478#M10393</link>
      <description>&lt;UL&gt;&lt;LI&gt;&amp;nbsp;Is it possible to do them in Splunk Enterprise trail license? Or Do we need to buy Splunk Observability module to monitor the open telemetry data?&lt;/LI&gt;&lt;LI&gt;[RL] You can get a 10GB dev license or a 50GB&amp;nbsp; - However, some are available depending on if you are a customer or not. But this is definitely a free Splunk license to get you started&lt;/LI&gt;&lt;LI&gt;Can we use a universal forwarder to collect the logs and trace or do we need to have the&amp;nbsp;Splunk OpenTelemetry Connector?&lt;/LI&gt;&lt;LI&gt;[RL] In our case we did not use the UF as we developed an exporter to send it directly to Splunk via HTTP event collector.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Share the link or document to ingest the open telemetry data logs into splunk.&lt;/LI&gt;&lt;LI&gt;[RL]&amp;nbsp; I will have to come back to you on this, as i cant fully remember where i got this from&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 19 Oct 2021 08:29:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/571478#M10393</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2021-10-19T08:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Using HTTP to get data into Splunk, but no host is set? - How do i set the host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/571482#M10394</link>
      <description>&lt;P&gt;thanks Robert for quick response on this, I had posted many questions regarding the same in Splunk answers.com but no one had responded back.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please guide me on the same on getting the open telemetry data in splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Oct 2021 08:36:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/571482#M10394</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2021-10-19T08:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Using HTTP to get data into Splunk, but no host is set? - How do i set the host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/572186#M10446</link>
      <description>&lt;P&gt;Hi Robert,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are doing a POC for our client, as per the client we wanted to ingest for&amp;nbsp;ForgeRock open telemetry data into Splunk.&amp;nbsp; For POC purpose we have installed the ForgeRock application and Splunk application are running in the google cloud instance machine (Trial version) but not sure how to on-board the data in to splunk.&amp;nbsp; So could please provide me some heads-up on how&amp;nbsp; to ingest the ForgeRock event data, metric and log into splunk.&amp;nbsp; Kindly share documents are steps which you had referred for ingesting the data in splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 05:24:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-HTTP-to-get-data-into-Splunk-but-no-host-is-set-How-do-i/m-p/572186#M10446</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2021-10-25T05:24:32Z</dc:date>
    </item>
  </channel>
</rss>

