<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Removed the syslog-host transform - but hostname is still getting pulled from /var/log/messages in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164675#M33397</link>
    <description>&lt;P&gt;Sourcetype=syslog results are picking up the short hostname from the /var/log/messages file.  I tried to correct this per the instructions here : &lt;A href="http://answers.splunk.com/answers/6895/can-i-prevent-the-default-index-time-extraction-for-the-host-field-to-occur-for-events-of-the-syslog-sourcetype"&gt;http://answers.splunk.com/answers/6895/can-i-prevent-the-default-index-time-extraction-for-the-host-field-to-occur-for-events-of-the-syslog-sourcetype&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Specifically, I now have a local/props.conf file.  The contents are as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog]
TRANSFORMS =
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The output looks correct, TRANSFORMS is null.  Yet the hostname is still getting set to the shortname, presumably from the shortname in the /var/log/messages file.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;splunk cmd btool props list syslog --debug&lt;BR /&gt;
Splunk_TA_ [syslog]&lt;BR /&gt;
system     ANNOTATE_PUNCT = True&lt;BR /&gt;
system     BREAK_ONLY_BEFORE = &lt;BR /&gt;
system     BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;BR /&gt;
system     TIME_FORMAT = %b %d %H:%M:%S&lt;BR /&gt;
system     TRANSFORMS = &lt;BR /&gt;
system     TRUNCATE = 10000&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Karla&lt;/P&gt;</description>
    <pubDate>Tue, 25 Feb 2014 13:06:26 GMT</pubDate>
    <dc:creator>di2esysadmin</dc:creator>
    <dc:date>2014-02-25T13:06:26Z</dc:date>
    <item>
      <title>Removed the syslog-host transform - but hostname is still getting pulled from /var/log/messages</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164675#M33397</link>
      <description>&lt;P&gt;Sourcetype=syslog results are picking up the short hostname from the /var/log/messages file.  I tried to correct this per the instructions here : &lt;A href="http://answers.splunk.com/answers/6895/can-i-prevent-the-default-index-time-extraction-for-the-host-field-to-occur-for-events-of-the-syslog-sourcetype"&gt;http://answers.splunk.com/answers/6895/can-i-prevent-the-default-index-time-extraction-for-the-host-field-to-occur-for-events-of-the-syslog-sourcetype&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Specifically, I now have a local/props.conf file.  The contents are as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog]
TRANSFORMS =
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The output looks correct, TRANSFORMS is null.  Yet the hostname is still getting set to the shortname, presumably from the shortname in the /var/log/messages file.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;splunk cmd btool props list syslog --debug&lt;BR /&gt;
Splunk_TA_ [syslog]&lt;BR /&gt;
system     ANNOTATE_PUNCT = True&lt;BR /&gt;
system     BREAK_ONLY_BEFORE = &lt;BR /&gt;
system     BREAK_ONLY_BEFORE_DATE = True&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;BR /&gt;
system     TIME_FORMAT = %b %d %H:%M:%S&lt;BR /&gt;
system     TRANSFORMS = &lt;BR /&gt;
system     TRUNCATE = 10000&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Karla&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2014 13:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164675#M33397</guid>
      <dc:creator>di2esysadmin</dc:creator>
      <dc:date>2014-02-25T13:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Removed the syslog-host transform - but hostname is still getting pulled from /var/log/messages</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164676#M33398</link>
      <description>&lt;P&gt;An additional related question . . . once I get this working the way I want, is it possible to change the hostname settings for data already indexed?  Or this that just a ridiculous question?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2014 14:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164676#M33398</guid>
      <dc:creator>di2esysadmin</dc:creator>
      <dc:date>2014-02-25T14:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Removed the syslog-host transform - but hostname is still getting pulled from /var/log/messages</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164677#M33399</link>
      <description>&lt;P&gt;To change already-indexed data you would need to remove it and re-index.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2014 20:29:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164677#M33399</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-02-25T20:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Removed the syslog-host transform - but hostname is still getting pulled from /var/log/messages</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164678#M33400</link>
      <description>&lt;P&gt;As I suspected. Thanks Martin.  &lt;/P&gt;

&lt;P&gt;Any suggestions on how to solve the problem I posed?  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2014 13:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164678#M33400</guid>
      <dc:creator>di2esysadmin</dc:creator>
      <dc:date>2014-02-27T13:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Removed the syslog-host transform - but hostname is still getting pulled from /var/log/messages</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164679#M33401</link>
      <description>&lt;P&gt;More information would be required to understand why this is not taking effect. First guess: did you make this change to props.conf on the forwarder? It needs to be configured on the indexer as the forwarder only handles the input stage. The following props.conf subset is applied on a universal/lightweight forwarder:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
sourcetype
CHARSET
NO_BINARY_CHECK
CHECK_METHOD
CHECK_FOR_HEADER
PREFIX_SOURCETYPE
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Reference:&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings"&gt;Where do I configure my Splunk settings?&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Verify the above, along with the final sourcetype. Look for other transforms that are related to the source or other attributes. Reply to your open support case if none of this helps to resolve the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 20:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164679#M33401</guid>
      <dc:creator>jreuter_splunk</dc:creator>
      <dc:date>2014-03-11T20:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Removed the syslog-host transform - but hostname is still getting pulled from /var/log/messages</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164680#M33402</link>
      <description>&lt;P&gt;I did NOT make it on the indexer.  Got it in one !  thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 11:33:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Removed-the-syslog-host-transform-but-hostname-is-still-getting/m-p/164680#M33402</guid>
      <dc:creator>di2esysadmin</dc:creator>
      <dc:date>2014-03-13T11:33:31Z</dc:date>
    </item>
  </channel>
</rss>

