<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412826#M73044</link>
    <description>&lt;P&gt;Unfortunately not&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2019 21:40:45 GMT</pubDate>
    <dc:creator>lhanich1</dc:creator>
    <dc:date>2019-03-01T21:40:45Z</dc:date>
    <item>
      <title>Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412822#M73040</link>
      <description>&lt;P&gt;I have a heavy forwarder that is capturing incoming logs from thousands of Linux hosts. The hosts are sending their OS logs. As known, Linux logs do not identify themselves with an IP in their log sources.&lt;/P&gt;

&lt;P&gt;Is their a way to capture their IP, from the receiving port, and parse it to a new field, such as src_ip?&lt;/P&gt;

&lt;P&gt;I know we can add identifying information in the hosts outputs.conf file but we are unable to do that due to the circumstances. &lt;/P&gt;

&lt;P&gt;The reason I am trying to accomplish this is because a lot of the hosts have a generic name such as "Linux" which is not of value as does not help from an analytical perspective.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 16:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412822#M73040</guid>
      <dc:creator>lhanich1</dc:creator>
      <dc:date>2019-03-01T16:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412823#M73041</link>
      <description>&lt;P&gt;Are you collecting all of the linux logs with a syslog server? If so, you could have you syslog server write the incoming data out to a directory with one of the parent directories labeled as the source IP. Then you could parse out the source IP from the &lt;CODE&gt;source&lt;/CODE&gt; field in Splunk&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 16:57:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412823#M73041</guid>
      <dc:creator>pkeenan87</dc:creator>
      <dc:date>2019-03-01T16:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412824#M73042</link>
      <description>&lt;P&gt;You can use connection_host = ip  in the inputs.conf to force the logs coming from that linux host to have 'ip' in 'host' field.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Inputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.4/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This way, you will be able to check the logs coming from each linux servers (using IP which is unique). Also, splunk assigns hostname upon install - check in $SPLUNK_HOME/etc/system/local/inputs.conf&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 17:45:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412824#M73042</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-01T17:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412825#M73043</link>
      <description>&lt;P&gt;and this would be added to the Heavy Forwarder inputs.conf correct?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 19:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412825#M73043</guid>
      <dc:creator>lhanich1</dc:creator>
      <dc:date>2019-03-01T19:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412826#M73044</link>
      <description>&lt;P&gt;Unfortunately not&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 21:40:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412826#M73044</guid>
      <dc:creator>lhanich1</dc:creator>
      <dc:date>2019-03-01T21:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412827#M73045</link>
      <description>&lt;P&gt;I notice the sending IP of the UF is being logged under _internal as sourceHost.... Any more ideas to capture that data and ensure its available in index=os?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2019 21:41:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412827#M73045</guid>
      <dc:creator>lhanich1</dc:creator>
      <dc:date>2019-03-01T21:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412828#M73046</link>
      <description>&lt;P&gt;Add connection_host=ip in each of the UF's input.conf&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 09:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412828#M73046</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-04T09:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412829#M73047</link>
      <description>&lt;P&gt;How exactly are collecting this data? You mention a Heavy Forwarder, but in the comments you are also talking about UF?&lt;/P&gt;

&lt;P&gt;Are the linux boxes sending syslog over UDP or TCP to the HF, or do you have a UF locally on each linux server, reading /var/log... and forwarding to a HF?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 09:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412829#M73047</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-04T09:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412830#M73048</link>
      <description>&lt;P&gt;The UFs on the hosts are forwarding to a HF&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 15:04:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412830#M73048</guid>
      <dc:creator>lhanich1</dc:creator>
      <dc:date>2019-03-04T15:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412831#M73049</link>
      <description>&lt;P&gt;How would that work @lakshman239 ? The UF is on each linux box itself, so either receiving syslog from local host, or using a file monitor input where that setting is not even available as far as I know.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 15:29:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412831#M73049</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-04T15:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412832#M73050</link>
      <description>&lt;P&gt;So, to recap:&lt;/P&gt;

&lt;P&gt;You have a bunch of linux hosts that:&lt;BR /&gt;
- don't always have a proper hostname&lt;BR /&gt;
- have a UF running that reads the local syslog and forward it to a central HF&lt;/P&gt;

&lt;P&gt;I don't think there really is a simple solution to this. I see a few options:&lt;BR /&gt;
- make sure your hosts have proper hostnames (which is useful for a lot more than just processing your logs)&lt;BR /&gt;
- configure each linux system's syslog settings such that it writes the IP address in the log message&lt;BR /&gt;
- configure each UF with a proper default host value in inputs.conf&lt;BR /&gt;
- on each linux system add a symlink to the log folder, where the symlink contains the hosts ip address as one of the path fragments, then point splunk at that symlink rather than the physical location, such that you can then use host_segment to get the ip address.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 15:37:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412832#M73050</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-04T15:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412833#M73051</link>
      <description>&lt;P&gt;Yes @FrankVl, as far as I understand, the UF is deployed on each of the linux data source and uses monitor stanza/inputs.conf to forward events. So, connection_host param should be able to help.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 16:00:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412833#M73051</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-03-04T16:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Capture and parse incoming Source IP's from Heavy Forwarder receiving incoming Linux logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412834#M73052</link>
      <description>&lt;P&gt;Except that connection_host is not available for monitor inputs, only for network inputs.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 16:26:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Capture-and-parse-incoming-Source-IP-s-from-Heavy-Forwarder/m-p/412834#M73052</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-03-04T16:26:17Z</dc:date>
    </item>
  </channel>
</rss>

