<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is my host_segment monitor configuration not working properly? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154371#M31377</link>
    <description>&lt;P&gt;Hmm, I see it's disabled so it shouldn't really matter. Try monitoring another directory outside of /var/log&lt;/P&gt;

&lt;P&gt;The host_segment you have looks OK though. Tried a different Splunk version in case it's a bug?&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jan 2015 18:32:25 GMT</pubDate>
    <dc:creator>mikaelbje</dc:creator>
    <dc:date>2015-01-05T18:32:25Z</dc:date>
    <item>
      <title>Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154364#M31370</link>
      <description>&lt;P&gt;Ok I read the documentation about using host_segment but it does not seem to be working properly&lt;/P&gt;

&lt;P&gt;Here is my stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/gns-dmz/network/]
host_segment = 5
sourcetype = cisco:iso
source = syslog
index = network
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Under the /var/log/gns-dmz/network there are like 10 directories which are the host names of the cisco switches/routers which are sending their syslogs to this syslog-ng server.  The stanza shows the host name as the name of the syslog-ng server and not the host_segment.  What I am doing wrong?&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
ed&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 23:06:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154364#M31370</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2014-12-19T23:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154365#M31371</link>
      <description>&lt;P&gt;The host_segment looks correct, but the sourcetype in your monitor stanza says &lt;EM&gt;cisco:iso&lt;/EM&gt;, not &lt;EM&gt;cisco:ios&lt;/EM&gt;. You might want to correct that.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2014 23:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154365#M31371</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2014-12-19T23:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154366#M31372</link>
      <description>&lt;P&gt;I fixed the sourcetype, which did nothing for my issue about the host_segment not working.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/gns-dmz/network/]
host_segment = 5
sourcetype = cisco:ios
source = syslog
index = network
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have 14 different sub-directories under /var/log/gns-dmz/network (all separate devices) and it still only shows up as ebs-syslog01 (name of syslog-ng server).  Not sure why it isn't working.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 17:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154366#M31372</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-01-05T17:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154367#M31373</link>
      <description>&lt;P&gt;Actually have have two separate host_segment stanzas that are not working on this particular host&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/gns-dmz/bluecat/]
host_segment = 5
index = bluecat
sourcetype = dns_syslog
source = syslog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So not sure what I am doing wrong&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 18:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154367#M31373</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-01-05T18:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154368#M31374</link>
      <description>&lt;P&gt;You should post comments on my answer, not answers to your question. This is not a forum, but a way to ask a question and get answers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;List the diretory contents of /var/log/gns-dmz/network and post them here.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Do you have another monitor stanza for /var/log/? This might be set up in i.e. the Splunk App for NIX . If this is the case it means you are monitoring the same files twice. Splunk will only index them once because it checks for duplicates before indexing.&lt;/LI&gt;
&lt;/OL&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 05 Jan 2015 18:19:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154368#M31374</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-01-05T18:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154369#M31375</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;[root@ebs-syslog01 network]# ls -lart
total 64
drwxr-xr-x  2 root root 4096 Dec  3 11:24 mamwangw0
drwxr-xr-x  2 root root 4096 Dec  3 11:33 amywangw0
drwxr-xr-x  2 root root 4096 Dec  3 11:33 wvwangw0a-loopback0
drwxr-xr-x  2 root root 4096 Dec  3 11:34 139.181.40.21
drwxr-xr-x  2 root root 4096 Dec  3 11:34 ieswangw0b
drwxr-xr-x  2 root root 4096 Dec  3 11:34 194.196.65.17
drwxr-xr-x  2 root root 4096 Dec  3 11:34 rumwangw0
drwxr-xr-x  2 root root 4096 Dec  3 11:34 tokwangw0
drwxr-xr-x  2 root root 4096 Dec  3 11:34 ieswangw0a
drwxr-xr-x  2 root root 4096 Dec  3 11:34 hsvwangw0-uloop
drwxr-xr-x  2 root root 4096 Dec  3 11:35 wvwangw0b-loopback0
drwxr-xr-x  2 root root 4096 Dec  3 11:35 wana-53-230-12-196
drwxr-xr-x  2 root root 4096 Dec  3 11:35 hsiwangw0
drwxr-xr-x  2 root root 4096 Dec  3 11:35 tw212-static81
drwxr-xr-x  4 root root 4096 Dec 19 14:28 ..
drwxr-xr-x 16 root root 4096 Dec 19 14:29 .
[root@ebs-syslog01 network]# 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Yes I have Splunk_TA_Nix installed on this server as well.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:31:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154369#M31375</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2020-09-28T18:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154370#M31376</link>
      <description>&lt;P&gt;I am assuming since Splunk_TA_Nix is installed and monitoring the following&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log]
whitelist=(\.log|log$|messages|secure|auth|mesg$|cron$|acpid$|\.out)
blacklist=(lastlog|anaconda\.syslog)
disabled = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;That I am not getting the host_segment to work as you have stated.  I will have to change the directory to one that is not being monitored or disable the Splunk_TA_Nix one, correct?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154370#M31376</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2020-09-28T18:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154371#M31377</link>
      <description>&lt;P&gt;Hmm, I see it's disabled so it shouldn't really matter. Try monitoring another directory outside of /var/log&lt;/P&gt;

&lt;P&gt;The host_segment you have looks OK though. Tried a different Splunk version in case it's a bug?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 18:32:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154371#M31377</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-01-05T18:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154372#M31378</link>
      <description>&lt;P&gt;I tried to use /var/testing/devices and then copied the 14 or so directories over and it seems to be working properly now.  Not sure why it isn't working in /var/log/gns-dmz&lt;/P&gt;

&lt;P&gt;-thanks&lt;BR /&gt;
ed&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 19:40:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154372#M31378</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-01-05T19:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154373#M31379</link>
      <description>&lt;P&gt;Great to hear that you got it working. It would be good if you could mark my answer as accepted &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 20:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154373#M31379</guid>
      <dc:creator>mikaelbje</dc:creator>
      <dc:date>2015-01-05T20:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154374#M31380</link>
      <description>&lt;P&gt;The reason why this is not working for you is that host_segment uses the source metadata to extract the segment from.  Since you are overriding the source by defining source = syslog, the default host will be used.&lt;BR /&gt;
Try removing the source definition and you should be good to go.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 15:58:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154374#M31380</guid>
      <dc:creator>ssmoot_splunk</dc:creator>
      <dc:date>2015-01-07T15:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my host_segment monitor configuration not working properly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154375#M31381</link>
      <description>&lt;P&gt;Yeah I found that out yesterday.  I removed the source line and everything started working as it should.&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
ed&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 15:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-host-segment-monitor-configuration-not-working/m-p/154375#M31381</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2015-01-07T15:59:38Z</dc:date>
    </item>
  </channel>
</rss>

