<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lost my host correlation  - alls logs seem sourced form local server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35958#M6553</link>
    <description>&lt;P&gt;Just to expand a bit on Simeon answer: in case #3 might it be that you had configured a "host=LOG01" line on the ubuntu server OUTSIDE the proper configuration stanza in inputs.conf?  That might have overridden the standard settings present into $SPLUNK_HOME/etc/system/local/inputs.conf&lt;/P&gt;</description>
    <pubDate>Tue, 24 Aug 2010 22:52:19 GMT</pubDate>
    <dc:creator>Paolo_Prigione</dc:creator>
    <dc:date>2010-08-24T22:52:19Z</dc:date>
    <item>
      <title>lost my host correlation  - alls logs seem sourced form local server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35956#M6551</link>
      <description>&lt;P&gt;Hello - &lt;/P&gt;

&lt;P&gt;I installed Splunk 4.1 on a Ubuntu 10.4 system  - nice and easy. I configured it to index ~ 7 files from the local /var/log/ path - splunk started to index - perfectly.&lt;/P&gt;

&lt;P&gt;After I was experimenting with a second splunk server to send Windows Logs as a forwarder (I configured sending and receiving on tcp 9997) my Splunk server seemed stopped to index my files in /var/log. The counters stopped going up - only Messages from "Host=LOG01" (my server) seemed to update. Looking closer I discovered that all Logs formerly correctly identified as coming form different sources - presented nicely on my Search/Summary start page were stale and turning up under the LOG01 host -  which is now displayed as the source of all log messages.&lt;/P&gt;

&lt;P&gt;How to get the "source recognition" going again - so h´that my Logs are indexed with the correct source again &lt;/P&gt;

&lt;P&gt;(you might guess that I am rather new to splunk)&lt;/P&gt;

&lt;P&gt;Kindest Regards
Robert&lt;/P&gt;

&lt;P&gt;PS: another thing I did was switching from Enterprise to Free License ... but the Host correlation seemed to got lost before that ...&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2010 20:54:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35956#M6551</guid>
      <dc:creator>robertblasey</dc:creator>
      <dc:date>2010-08-24T20:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: lost my host correlation  - alls logs seem sourced form local server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35957#M6552</link>
      <description>&lt;P&gt;There are a couple ways Splunk determines hostname.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Via an extracted and indexed field&lt;/LI&gt;
&lt;LI&gt;Via an extracted non-indexed field&lt;/LI&gt;
&lt;LI&gt;At index time via manual setting&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;It sounds like you have scenario #3, where an input setting has a "host" value set to something.  This will force all data on that input to be set to that host value. &lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2010 22:20:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35957#M6552</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-08-24T22:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: lost my host correlation  - alls logs seem sourced form local server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35958#M6553</link>
      <description>&lt;P&gt;Just to expand a bit on Simeon answer: in case #3 might it be that you had configured a "host=LOG01" line on the ubuntu server OUTSIDE the proper configuration stanza in inputs.conf?  That might have overridden the standard settings present into $SPLUNK_HOME/etc/system/local/inputs.conf&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2010 22:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35958#M6553</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2010-08-24T22:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: lost my host correlation  - alls logs seem sourced form local server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35959#M6554</link>
      <description>&lt;P&gt;hi  Paolo - hi Simeon - thanks a lot for your help.&lt;/P&gt;

&lt;P&gt;I edited my "$SPLUNK_HOME/etc/system/local/inputs.conf" and deleted the entry "host = LOG01" under "[default]" - just as you suspected .. I restarted splunk - but the logs are still all showing up under LOG01.&lt;/P&gt;

&lt;P&gt;Physically the all my logs are on LOG01 - collected and rotated by Sysklogd - the default Ubuntu Syslogger. So Splunk just forgot how to idetifiy the true source. &lt;/P&gt;

&lt;P&gt;I am not really sure what to look for. I not familiar with the term "stanza" - I will grep for a LOG01 - maybe I find some other input.conf's&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2010 22:21:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35959#M6554</guid>
      <dc:creator>robertblasey</dc:creator>
      <dc:date>2010-08-25T22:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: lost my host correlation  - alls logs seem sourced form local server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35960#M6555</link>
      <description>&lt;P&gt;Hello Robert.  Did you ever resolve this issue?  I am experiencing this as well except that source has been Splunk host since turning up.&lt;/P&gt;

&lt;P&gt;Thanks,
Chris&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2011 04:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/lost-my-host-correlation-alls-logs-seem-sourced-form-local/m-p/35960#M6555</guid>
      <dc:creator>calyope7</dc:creator>
      <dc:date>2011-04-13T04:41:47Z</dc:date>
    </item>
  </channel>
</rss>

