<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: /var/log/messages associated with index host NOT the correct source host in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91642#M19043</link>
    <description>&lt;P&gt;What sourcetype do you have for /var/log/messages?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jan 2013 22:49:56 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-01-17T22:49:56Z</dc:date>
    <item>
      <title>/var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91641#M19042</link>
      <description>&lt;P&gt;I have two dozen UF linux systems.  All of them are picking up /var/log/messages and sending it to my indexer (the one and only "splunk" host).&lt;/P&gt;

&lt;P&gt;All of the /var/log/messages entries are indexed as coming from host=splunk.&lt;/P&gt;

&lt;P&gt;WHY?&lt;/P&gt;

&lt;P&gt;HELP!&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2013 22:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91641#M19042</guid>
      <dc:creator>krussell101</dc:creator>
      <dc:date>2013-01-17T22:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91642#M19043</link>
      <description>&lt;P&gt;What sourcetype do you have for /var/log/messages?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2013 22:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91642#M19043</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-17T22:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91643#M19044</link>
      <description>&lt;P&gt;sourcetype = syslog&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2013 20:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91643#M19044</guid>
      <dc:creator>krussell101</dc:creator>
      <dc:date>2013-01-18T20:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91644#M19045</link>
      <description>&lt;P&gt;Is there a hostname defined on your UF's in /opt/splunkforwarder/etc/system/local/inputs.conf?&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jan 2013 23:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91644#M19045</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2013-01-20T23:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91645#M19046</link>
      <description>&lt;P&gt;No.  they pick up the local hostname.  Which is how I want it to behave.  All other files in /var/log come over with the correct hostname.  This is the only file which is attributed to the incorrect host.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2013 14:05:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91645#M19046</guid>
      <dc:creator>krussell101</dc:creator>
      <dc:date>2013-01-22T14:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91646#M19047</link>
      <description>&lt;P&gt;This isn't an answer&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2013 23:48:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91646#M19047</guid>
      <dc:creator>krussell101</dc:creator>
      <dc:date>2013-02-04T23:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91647#M19048</link>
      <description>&lt;P&gt;Have any stray props.conf/transforms.conf on the indexer? Is this all of your forwarders or only some of them?&lt;/P&gt;

&lt;P&gt;Try "splunk btool transforms list --debug &amp;gt; out.txt" on your indexer and grep for MetaData:Host in out.txt. It possible that there's a transform setting the host value to splunk&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 01:11:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91647#M19048</guid>
      <dc:creator>BryanBerry</dc:creator>
      <dc:date>2013-02-05T01:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91648#M19049</link>
      <description>&lt;P&gt;This is occurring to /var/log/messages from all of my forwarders.  &lt;/P&gt;

&lt;P&gt;transforms list output:&lt;/P&gt;

&lt;P&gt;system     [syslog-host]&lt;BR /&gt;
system     CAN_OPTIMIZE = True&lt;BR /&gt;
system     CLEAN_KEYS = True&lt;BR /&gt;
system     DEFAULT_VALUE = &lt;BR /&gt;
system     DEST_KEY = MetaData:Host&lt;BR /&gt;
system     FORMAT = host::splunk-mydomain.com&lt;/P&gt;

&lt;P&gt;Is this taking everything of sourcetype syslog and attributing it to another host?&lt;/P&gt;

&lt;P&gt;Cool!  So now I have to unset that somehow.  Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:14:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91648#M19049</guid>
      <dc:creator>krussell101</dc:creator>
      <dc:date>2020-09-28T13:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91649#M19050</link>
      <description>&lt;P&gt;Any hints on where this may have snuck in?  I don't recall doing any transforms at all.   Will this be on my forwarders somewhere or on the indexer?&lt;/P&gt;

&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 12:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91649#M19050</guid>
      <dc:creator>krussell101</dc:creator>
      <dc:date>2013-02-05T12:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91650#M19051</link>
      <description>&lt;P&gt;FOUND IT!  THANK YOU!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 12:14:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91650#M19051</guid>
      <dc:creator>krussell101</dc:creator>
      <dc:date>2013-02-05T12:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: /var/log/messages associated with index host NOT the correct source host</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91651#M19052</link>
      <description>&lt;P&gt;Huh, that is very odd. Was that in etc/system/local/transforms.conf or default? Did you find how that got in there? I'm curious about the cause as well.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 22:13:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/var-log-messages-associated-with-index-host-NOT-the-correct/m-p/91651#M19052</guid>
      <dc:creator>BryanBerry</dc:creator>
      <dc:date>2013-02-05T22:13:32Z</dc:date>
    </item>
  </channel>
</rss>

