<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: getting logs from unexcepted hosts in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600615#M104695</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;As I'm having a test setup, I have deleted all logs. And now I'm only getting logs from defined hosts.&lt;/P&gt;&lt;P&gt;I'll keep it under observation, and will see if it occurs again.&lt;/P&gt;&lt;P&gt;Thanks for your help &amp;amp; detailed explanation.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 05 Jun 2022 15:31:57 GMT</pubDate>
    <dc:creator>__Sebastian</dc:creator>
    <dc:date>2022-06-05T15:31:57Z</dc:date>
    <item>
      <title>Why am I getting logs from unexcepted hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600585#M104690</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;I have integrated UF with splunk v8.2 but getting unnecessary host from where I'm getting logs. Not sure how they started sending logs. Is there a way I can stop and check it, why it started and how I can stop them? Below screenshot for reference&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="__Sebastian_0-1654405254684.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19945iA423AD83078B0598/image-size/medium?v=v2&amp;amp;px=400" role="button" title="__Sebastian_0-1654405254684.png" alt="__Sebastian_0-1654405254684.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 03:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600585#M104690</guid>
      <dc:creator>__Sebastian</dc:creator>
      <dc:date>2022-06-06T03:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: getting logs from unexcepted hosts</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600592#M104692</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234072"&gt;@__Sebastian&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the first ting you should do is to understand which kind of unwanted logs you are receiving. from Forwarders or from syslogs.&lt;/P&gt;&lt;P&gt;Viewing you screenshot the seems to be syslogs.&lt;/P&gt;&lt;P&gt;Anyway, if the come from syslogs, you have to go in those systems and stop syslogs sending.&lt;/P&gt;&lt;P&gt;If instead they come from Forwarders, you have to stop (and eventually remove) the Forwarder on these systems.&lt;/P&gt;&lt;P&gt;In addition I can say that the hostnames are very strange, maybe is there an host overriding configuration o your Indexers?&lt;/P&gt;&lt;P&gt;You can check this, viewing props.conf and transforms.conf on your Indexers (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 05:50:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600592#M104692</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-05T05:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: getting logs from unexcepted hosts</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600595#M104693</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;for a quick response. I have just installed UF on CentOS 8 and enabled only /var/log in inputs.conf.&lt;/P&gt;&lt;P&gt;the hostname "uf" is what I'm expecting but not sure from why I'm getting data from other hosts. And I don't have any host in my setup with such names. Is there way, I can check why it's fetching data from these, when I have only 1 entry in my inputs.conf&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="__Sebastian_0-1654408748697.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19946i5F66F1FEB5C42465/image-size/medium?v=v2&amp;amp;px=400" role="button" title="__Sebastian_0-1654408748697.png" alt="__Sebastian_0-1654408748697.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;__Sebastian&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 06:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600595#M104693</guid>
      <dc:creator>__Sebastian</dc:creator>
      <dc:date>2022-06-05T06:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: getting logs from unexcepted hosts</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600601#M104694</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234072"&gt;@__Sebastian&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;for logs coming from Forwarders, hostname is usually setted in:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;by default:&lt;UL&gt;&lt;LI&gt;$SPLUNK_HOME/system/local/server.conf&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;$SPLUNK_HOME/system/local/inputs.conf&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;on UF overriding:&lt;UL&gt;&lt;LI&gt;all inputs.conf&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;in Indexers or (uf present) on Heavy Forwarders&lt;UL&gt;&lt;LI&gt;on props.conf.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;for logs coming from syslogs (usually the ones with an IP address as hostname) are setted in inputs.conf.&lt;/P&gt;&lt;P&gt;So you should read the logs with unexpected hostnames and understand what kind of logs they are: syslogs or from Forwarders.&lt;/P&gt;&lt;P&gt;Then you can analyze the conf files to underatand where the hostname is conigured.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 09:34:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600601#M104694</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-05T09:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: getting logs from unexcepted hosts</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600615#M104695</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;As I'm having a test setup, I have deleted all logs. And now I'm only getting logs from defined hosts.&lt;/P&gt;&lt;P&gt;I'll keep it under observation, and will see if it occurs again.&lt;/P&gt;&lt;P&gt;Thanks for your help &amp;amp; detailed explanation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 15:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600615#M104695</guid>
      <dc:creator>__Sebastian</dc:creator>
      <dc:date>2022-06-05T15:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: getting logs from unexcepted hosts</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600617#M104696</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234072"&gt;@__Sebastian&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;when you'll finish the observation, remember to accept an answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated ,-)&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 15:35:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600617#M104696</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-06-05T15:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: getting logs from unexcepted hosts</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600619#M104697</link>
      <description>&lt;P&gt;If you enabled /var/log in general as a single sourcetype, you will get many different types of logs ingested but treated the same way. That's not the way to go. Don't mix different types&amp;nbsp; of input data within a single inputs.conf stanza.&lt;/P&gt;&lt;P&gt;You should have a separate well-defined stanza for all "syslog-like" files like /var/log/messages, separate for other types (I don't know what's happening on your system and what kinds of data you're pulling). Otherwise all those different files from /var/log are getting treated the same way even though they contain data in different formats. That's why your "host" is getting parsed wrongly from many events.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 17:38:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-getting-logs-from-unexcepted-hosts/m-p/600619#M104697</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-06-05T17:38:36Z</dc:date>
    </item>
  </channel>
</rss>

