<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting host to hostname vs IP address in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Setting-host-to-hostname-vs-IP-address/m-p/107358#M22575</link>
    <description>&lt;P&gt;I had the same problem, even if I told it not to.  It sorta double dips your hostnames, especially if you already had the hostname show up prior to enabling syslog.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2013 20:22:18 GMT</pubDate>
    <dc:creator>gnovak</dc:creator>
    <dc:date>2013-04-26T20:22:18Z</dc:date>
    <item>
      <title>Setting host to hostname vs IP address</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-host-to-hostname-vs-IP-address/m-p/107357#M22574</link>
      <description>&lt;P&gt;I have different devices sending data via syslog. &lt;/P&gt;

&lt;P&gt;Current Stanza Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[udp//IP:PORT]
host = hostname
sourcetype = syslog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, events still show up as host = ip address. Is there another place to do this?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2013 15:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-host-to-hostname-vs-IP-address/m-p/107357#M22574</guid>
      <dc:creator>agodoy</dc:creator>
      <dc:date>2013-04-26T15:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Setting host to hostname vs IP address</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-host-to-hostname-vs-IP-address/m-p/107358#M22575</link>
      <description>&lt;P&gt;I had the same problem, even if I told it not to.  It sorta double dips your hostnames, especially if you already had the hostname show up prior to enabling syslog.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2013 20:22:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-host-to-hostname-vs-IP-address/m-p/107358#M22575</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2013-04-26T20:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: Setting host to hostname vs IP address</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-host-to-hostname-vs-IP-address/m-p/107359#M22576</link>
      <description>&lt;P&gt;It seems that the process is not as straight forward as I thought for syslog devices.&lt;/P&gt;

&lt;P&gt;See this blog post:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2008/04/16/overriding-default-syslog-host-extraction/"&gt;http://blogs.splunk.com/2008/04/16/overriding-default-syslog-host-extraction/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Now trying to figure out how to do this in a Cluster.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2013 19:23:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-host-to-hostname-vs-IP-address/m-p/107359#M22576</guid>
      <dc:creator>agodoy</dc:creator>
      <dc:date>2013-06-28T19:23:37Z</dc:date>
    </item>
  </channel>
</rss>

