<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog Output missing header in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Output-missing-header/m-p/533871#M89640</link>
    <description>&lt;P&gt;Hello All&lt;/P&gt;&lt;P&gt;I found a similar question but did not see an answer.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/No-time-or-host-in-forwarded-syslog-messages/m-p/52627" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/No-time-or-host-in-forwarded-syslog-messages/m-p/52627&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I am forwarding Checkpoint logs that are coming in via tcp://514 and I am trying to forward the data to an HA syslog-ng environment.&amp;nbsp; There is a NetScaler in front two different syslog-ng servers with round robin load balancing happening.&amp;nbsp; I disabled the second syslog-ng host so that all logs get sent to sys-01.&amp;nbsp; I see the following coming in:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Msg: 2020-12-22 18:30 host-blah-blah.xxx.xxx.xxx.com time=1608661800|hostname=logger|product=Firewall|layer_name=xx-stl-private Security|layer_uuid=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx|match_id=197|parent_rule=0|rule_action=Accept|rule_uid=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx|action=Accept|conn_direction=Internal|ifdir=inbound|ifname=eth2-01.716|logid=0|loguid={0x00000000,0x00,0x0000000,0xc0000000}|origin=xxx.xxx.xxx.xxx|originsicname=blah_gw-stl-prv|sequencenum=199|time=1608661800|version=5|dst=xxx.xxx.xxx.xxx|log_delay=1608661800|proto=6|s_port=47298|service=7031|src=xxx.xxx.xxx.xxx|&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the previous link that seems to be a bug, but I am going to assume that it is an old bug and should not exist in Splunk version 8.0.6.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way in the outputs.conf to force a header that has the hostname?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;ed&lt;/P&gt;</description>
    <pubDate>Tue, 22 Dec 2020 18:49:20 GMT</pubDate>
    <dc:creator>edwardrose</dc:creator>
    <dc:date>2020-12-22T18:49:20Z</dc:date>
    <item>
      <title>Syslog Output missing header</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Output-missing-header/m-p/533871#M89640</link>
      <description>&lt;P&gt;Hello All&lt;/P&gt;&lt;P&gt;I found a similar question but did not see an answer.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/No-time-or-host-in-forwarded-syslog-messages/m-p/52627" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/No-time-or-host-in-forwarded-syslog-messages/m-p/52627&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I am forwarding Checkpoint logs that are coming in via tcp://514 and I am trying to forward the data to an HA syslog-ng environment.&amp;nbsp; There is a NetScaler in front two different syslog-ng servers with round robin load balancing happening.&amp;nbsp; I disabled the second syslog-ng host so that all logs get sent to sys-01.&amp;nbsp; I see the following coming in:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Msg: 2020-12-22 18:30 host-blah-blah.xxx.xxx.xxx.com time=1608661800|hostname=logger|product=Firewall|layer_name=xx-stl-private Security|layer_uuid=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx|match_id=197|parent_rule=0|rule_action=Accept|rule_uid=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx|action=Accept|conn_direction=Internal|ifdir=inbound|ifname=eth2-01.716|logid=0|loguid={0x00000000,0x00,0x0000000,0xc0000000}|origin=xxx.xxx.xxx.xxx|originsicname=blah_gw-stl-prv|sequencenum=199|time=1608661800|version=5|dst=xxx.xxx.xxx.xxx|log_delay=1608661800|proto=6|s_port=47298|service=7031|src=xxx.xxx.xxx.xxx|&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the previous link that seems to be a bug, but I am going to assume that it is an old bug and should not exist in Splunk version 8.0.6.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way in the outputs.conf to force a header that has the hostname?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;ed&lt;/P&gt;</description>
      <pubDate>Tue, 22 Dec 2020 18:49:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Output-missing-header/m-p/533871#M89640</guid>
      <dc:creator>edwardrose</dc:creator>
      <dc:date>2020-12-22T18:49:20Z</dc:date>
    </item>
  </channel>
</rss>

