<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forwarder overwrites log source IP, inserting its own UF ip when forwarding logs to search head in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505939#M86183</link>
    <description>&lt;P&gt;Thanx !&lt;/P&gt;&lt;P&gt;I checked the inputs.conf and it is already solved there since we put there that the log source should be the 7th parameter of the folder holding its logs which is the IP of the actual log source.&lt;/P&gt;&lt;P&gt;Solved then !&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jun 2020 11:29:57 GMT</pubDate>
    <dc:creator>leebsr</dc:creator>
    <dc:date>2020-06-24T11:29:57Z</dc:date>
    <item>
      <title>Universal forwarder overwrites log source IP, inserting its own UF ip when forwarding logs to search head</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505029#M86036</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I have a gd issue here. My universal forwarder sends logs to a splunk search head, and the search head sees the logs with the IP of the universal forwarder as if it were the log source, when it is actually not, it is just forwarding logs from the sources.&lt;/P&gt;&lt;P&gt;How can I get rid of this so I can see at the searches the real log source IPs ??&lt;/P&gt;&lt;P&gt;Is there a reason why this IP overwrite could be useful ?&amp;nbsp; I dont see it and for now what I need is to have real IPs on the search heads.&lt;/P&gt;&lt;P&gt;Craving for a solution&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 16:23:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505029#M86036</guid>
      <dc:creator>leebsr</dc:creator>
      <dc:date>2020-06-18T16:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder overwrites log source IP, inserting its own UF ip when forwarding logs to search head</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505031#M86037</link>
      <description>Please tell us more about your Splunk environment? How are the data sources getting to the UF? Are you using the UF as a syslog server? If so, that's not a good practice.&lt;BR /&gt;Why is the UF sending data to the SH instead of the indexer(s)?</description>
      <pubDate>Thu, 18 Jun 2020 16:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505031#M86037</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-18T16:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder overwrites log source IP, inserting its own UF ip when forwarding logs to search head</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505036#M86038</link>
      <description>&lt;P&gt;Hi richgalloway 1st of all many thanks for your quick answer.&lt;/P&gt;&lt;P&gt;Correct in this environment I belive that they have configured the UF as well as a syslog server. I need to confirm this though.&lt;/P&gt;&lt;P&gt;Could you please give further details on the correct architeture for the UF and the log source ---&amp;gt; splunk flow ?&lt;/P&gt;&lt;P&gt;I believe that what you mean in your second part of the answer is that the uf should be pointing and sending logs to the inderxers and later on when querying the sh, it will send the query to the indexers which will perform the dirty job, right ? and then indexers will send their output to the sh correct ? is that the right arch ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 17:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505036#M86038</guid>
      <dc:creator>leebsr</dc:creator>
      <dc:date>2020-06-18T17:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder overwrites log source IP, inserting its own UF ip when forwarding logs to search head</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505042#M86040</link>
      <description>&lt;P&gt;UF as a syslog server has a number of issues, but your configuration of a UF installed on a dedicated syslog server is considered Best Practice.&amp;nbsp; Thanks for clarifying that.&lt;/P&gt;&lt;P&gt;Can you share the inputs.conf settings on the UF for one of the problem data sources?&lt;/P&gt;&lt;P&gt;Yes, forwarders (and search heads) should be forwarding data to indexers.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 17:22:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505042#M86040</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-18T17:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder overwrites log source IP, inserting its own UF ip when forwarding logs to search head</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505939#M86183</link>
      <description>&lt;P&gt;Thanx !&lt;/P&gt;&lt;P&gt;I checked the inputs.conf and it is already solved there since we put there that the log source should be the 7th parameter of the folder holding its logs which is the IP of the actual log source.&lt;/P&gt;&lt;P&gt;Solved then !&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 11:29:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-overwrites-log-source-IP-inserting-its-own/m-p/505939#M86183</guid>
      <dc:creator>leebsr</dc:creator>
      <dc:date>2020-06-24T11:29:57Z</dc:date>
    </item>
  </channel>
</rss>

