<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search by host (all indexed data Hosts list) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Search-by-host-all-indexed-data-Hosts-list/m-p/11311#M558</link>
    <description>&lt;P&gt;Hi Dragan,&lt;/P&gt;

&lt;P&gt;If you configure for this input, set host = segment in path, it should automatically figure out your syslog hosts.  Since the input has already been created you won't be able to edit it from the UI.  However, you can modify the monitor input directly in $SPLUNK_HOME/etc/.../local/inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/HOSTS]
host_segment = 5
sourcetype = syslog
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 13 Apr 2010 19:02:53 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-04-13T19:02:53Z</dc:date>
    <item>
      <title>Search by host (all indexed data Hosts list)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Search-by-host-all-indexed-data-Hosts-list/m-p/11310#M557</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have syslog_ng server (sles 10). Everything is logged in this way:&lt;/P&gt;

&lt;P&gt;/var/log/HOSTS/xx-yy/hostname or ip/log file&lt;/P&gt;

&lt;P&gt;I have 10 syslog clients and everything works fine. Folder for every host is created...&lt;/P&gt;

&lt;P&gt;Then i installed splunk and cofigured data inputs /var/log/HOSTS&lt;/P&gt;

&lt;P&gt;When i go to splunk&amp;gt;search in all indexed data under sources i have all my log files but in Hosts section i have only one host, my sles syslog server where all messages are stored together.&lt;/P&gt;

&lt;P&gt;I would like to have all my syslog clients under Hosts section to browse messages separately by client (host). Is it possible?&lt;/P&gt;

&lt;P&gt;Thanks in advanced&lt;/P&gt;

&lt;P&gt;Dragan &lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2010 18:53:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Search-by-host-all-indexed-data-Hosts-list/m-p/11310#M557</guid>
      <dc:creator>mudricd</dc:creator>
      <dc:date>2010-04-13T18:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: Search by host (all indexed data Hosts list)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Search-by-host-all-indexed-data-Hosts-list/m-p/11311#M558</link>
      <description>&lt;P&gt;Hi Dragan,&lt;/P&gt;

&lt;P&gt;If you configure for this input, set host = segment in path, it should automatically figure out your syslog hosts.  Since the input has already been created you won't be able to edit it from the UI.  However, you can modify the monitor input directly in $SPLUNK_HOME/etc/.../local/inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/log/HOSTS]
host_segment = 5
sourcetype = syslog
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:02:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Search-by-host-all-indexed-data-Hosts-list/m-p/11311#M558</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-04-13T19:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Search by host (all indexed data Hosts list)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Search-by-host-all-indexed-data-Hosts-list/m-p/11312#M559</link>
      <description>&lt;P&gt;Thanks a lot man!&lt;BR /&gt;
Everything works fine now! &lt;BR /&gt;
My hosts are finally showing up &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2010 19:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Search-by-host-all-indexed-data-Hosts-list/m-p/11312#M559</guid>
      <dc:creator>mudricd</dc:creator>
      <dc:date>2010-04-13T19:47:47Z</dc:date>
    </item>
  </channel>
</rss>

