<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Retrieving logs from all hosts in Splunk cloud, instead of one in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Retrieving-logs-from-all-hosts-in-Splunk-cloud-instead-of-one/m-p/463871#M79997</link>
    <description>&lt;P&gt;Yes, this is normal default behavior but it is definitely incorrect for your use case.  You need to override the &lt;CODE&gt;host&lt;/CODE&gt; value and take it from inside of the event or from the connection.  See here for how we do it:&lt;BR /&gt;
&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Sep 2019 17:44:37 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-09-18T17:44:37Z</dc:date>
    <item>
      <title>Retrieving logs from all hosts in Splunk cloud, instead of one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retrieving-logs-from-all-hosts-in-Splunk-cloud-instead-of-one/m-p/463869#M79995</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Tanium is sending logs to our only syslog server and we have created a folder in that server (let us say a)  so in Splunk cloud it should show as host = a, but in Splunk cloud, we could see hostname containing different syslog servers. Is it a bug?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 12:34:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retrieving-logs-from-all-hosts-in-Splunk-cloud-instead-of-one/m-p/463869#M79995</guid>
      <dc:creator>VijaySrrie</dc:creator>
      <dc:date>2019-08-26T12:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieving logs from all hosts in Splunk cloud, instead of one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retrieving-logs-from-all-hosts-in-Splunk-cloud-instead-of-one/m-p/463870#M79996</link>
      <description>&lt;P&gt;It depends on how the data is being handled during index time. You can change the host field in index time with props/transforms confs and you can also set the host as a segment of the path your monitoring. &lt;/P&gt;

&lt;P&gt;Several TAs bring some kind of field manipulation out of the box (e.g. you index data with source type pan_logs and it ends up as pan:traffic, pan:system, etc). Same logic can be applied to other fields in index time (e.g. index (for data routing), host (to correctly assign the host name), etc. )&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 12:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retrieving-logs-from-all-hosts-in-Splunk-cloud-instead-of-one/m-p/463870#M79996</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2019-08-26T12:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Retrieving logs from all hosts in Splunk cloud, instead of one</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Retrieving-logs-from-all-hosts-in-Splunk-cloud-instead-of-one/m-p/463871#M79997</link>
      <description>&lt;P&gt;Yes, this is normal default behavior but it is definitely incorrect for your use case.  You need to override the &lt;CODE&gt;host&lt;/CODE&gt; value and take it from inside of the event or from the connection.  See here for how we do it:&lt;BR /&gt;
&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 17:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Retrieving-logs-from-all-hosts-in-Splunk-cloud-instead-of-one/m-p/463871#M79997</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-09-18T17:44:37Z</dc:date>
    </item>
  </channel>
</rss>

