<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog field over-rides host_segment in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58229#M11420</link>
    <description>&lt;P&gt;Worked a treat. Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 25 May 2012 12:51:58 GMT</pubDate>
    <dc:creator>inglisn</dc:creator>
    <dc:date>2012-05-25T12:51:58Z</dc:date>
    <item>
      <title>syslog field over-rides host_segment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58226#M11417</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have a syslog server (Centos 6) with splunk 4.3.1 that receives syslog using the rsyslog daemon. The folder structure is /var/log/remote/1.2.3.4/syslog.log and I want to use the source IP address as the 'host' field. &lt;/P&gt;

&lt;P&gt;The docs say to use host_segment, which I've done (inputs.conf shown below) but this seems to be ignored in favour of the syslog event hostname which could be IP, or could be hostname. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/remote]
blacklist = *.gz
disabled = false
followTail = 0
index = test
sourcetype = syslog
whitelist = *.log
host_segment = 4
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've also tried manually setting it to a fixed string, and it still prefers the syslog headings. Sometimes the syslog message is that the last message repeated n times, in which case host=last.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2012 13:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58226#M11417</guid>
      <dc:creator>inglisn</dc:creator>
      <dc:date>2012-05-23T13:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: syslog field over-rides host_segment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58227#M11418</link>
      <description>&lt;P&gt;You can disable the syslog-host transform for the syslog sourcetype by adding the following stanza to your $SPLUNK_HOME/etc/system/local/props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog]
TRANSFORMS = 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 23 May 2012 13:30:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58227#M11418</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2012-05-23T13:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: syslog field over-rides host_segment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58228#M11419</link>
      <description>&lt;P&gt;More info:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2008/04/16/overriding-default-syslog-host-extraction/"&gt;http://blogs.splunk.com/2008/04/16/overriding-default-syslog-host-extraction/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2012 15:05:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58228#M11419</guid>
      <dc:creator>dshpritz</dc:creator>
      <dc:date>2012-05-23T15:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: syslog field over-rides host_segment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58229#M11420</link>
      <description>&lt;P&gt;Worked a treat. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 25 May 2012 12:51:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58229#M11420</guid>
      <dc:creator>inglisn</dc:creator>
      <dc:date>2012-05-25T12:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: syslog field over-rides host_segment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58230#M11421</link>
      <description>&lt;P&gt;I have the same problem (Why isn't this in the official docs for host_segment?) but I don't want to change all events of the syslog sourcetype. What should I do?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 20:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-field-over-rides-host-segment/m-p/58230#M11421</guid>
      <dc:creator>bnorthway</dc:creator>
      <dc:date>2015-06-26T20:13:04Z</dc:date>
    </item>
  </channel>
</rss>

