<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: host is not being extracted from linux_secure in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432125#M95295</link>
    <description>&lt;P&gt;Hello @arsalanj &lt;/P&gt;

&lt;P&gt;Try this add-on specifically for Linux Secure&lt;BR /&gt;
    &lt;A href="https://splunkbase.splunk.com/app/3476/"&gt;https://splunkbase.splunk.com/app/3476/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Mostly it will help you out&lt;/P&gt;</description>
    <pubDate>Fri, 26 Apr 2019 06:43:49 GMT</pubDate>
    <dc:creator>vishaltaneja070</dc:creator>
    <dc:date>2019-04-26T06:43:49Z</dc:date>
    <item>
      <title>host is not being extracted from linux_secure</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432124#M95294</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;We are forwarding all of our /var/log/secure logs to a syslog server "syslogserver.local " and from there it's being forwarded to Splunk over a TCP port.&lt;BR /&gt;
The Splunk is configured as a single instance.&lt;BR /&gt;
in Data Inputs I created a TCP listener and the source type is linux_secure.&lt;/P&gt;

&lt;P&gt;In the search app most of the fields are getting extracted except the hostname "myhost " .&lt;BR /&gt;
The host field only shows the name of that syslog server instead of the name of the server that alert was generated.&lt;/P&gt;

&lt;P&gt;&amp;lt;85&amp;gt;Apr 25 15:22:03 myhost unix_chkpwd[20316]: password check failed for user (jon.doe)&lt;BR /&gt;
date_hour = 15 date_mday =  25 date_minute =    22 date_month = april date_second = 3 date_wday =   thursday date_year =    2019 date_zone =    local eventtype =   err0r   error   eventtype = nix_errors  error   eventtype = nix_security    os  unix host = syslogserver local index =  linux_index linecount = 1 pid = 20316 process = unix_chkpwd source =    tcp:40515 sourcetype =  linux_secure splunk_server =     splunk.local src = syslogserver.local  tag =   error   tag =   os  tag =   unix timeendpos =   20 timestartpos =   4&lt;/P&gt;

&lt;P&gt;As you can see, the value of the host and src are the same.&lt;BR /&gt;
syslogserver.local is the server that aggregates all the syslogs. and there is no field that shows "myhost"&lt;/P&gt;

&lt;P&gt;Any ideas of where the problem might be?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:16:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432124#M95294</guid>
      <dc:creator>arsalanj</dc:creator>
      <dc:date>2020-09-30T00:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: host is not being extracted from linux_secure</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432125#M95295</link>
      <description>&lt;P&gt;Hello @arsalanj &lt;/P&gt;

&lt;P&gt;Try this add-on specifically for Linux Secure&lt;BR /&gt;
    &lt;A href="https://splunkbase.splunk.com/app/3476/"&gt;https://splunkbase.splunk.com/app/3476/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Mostly it will help you out&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2019 06:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432125#M95295</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2019-04-26T06:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: host is not being extracted from linux_secure</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432126#M95296</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49295"&gt;@vishaltaneja070&lt;/a&gt;11993,&lt;/P&gt;

&lt;P&gt;actually, I already have it installed, but it doesn't make any difference.&lt;BR /&gt;
When the source type is syslog, it can extract the host values.&lt;BR /&gt;
I already tried the following: &lt;BR /&gt;
App context=TA-linux_secure with source type linux_secure&lt;BR /&gt;
App context=Splunk_TA_nix  with source type linux_secure&lt;BR /&gt;
They both can't extract the host value.&lt;BR /&gt;
But if I choose syslog as source type, it can extract the host value no matter what app context I select.&lt;BR /&gt;
So what is the right of doing this?&lt;BR /&gt;
shouldn't we change something in transform.conf or somewhere else?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:17:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432126#M95296</guid>
      <dc:creator>arsalanj</dc:creator>
      <dc:date>2020-09-30T00:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: host is not being extracted from linux_secure</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432127#M95297</link>
      <description>&lt;P&gt;I Just deleted both  Splunk_TA_nix and  TA-linux_secure.&lt;BR /&gt;
My source type is syslog and it extracts the host values and I see no difference from when I had those TAs.&lt;/P&gt;

&lt;P&gt;My selected fields and interesting fields are the same before and after deleting those TAs with syslog source type.&lt;/P&gt;

&lt;P&gt;Now I'm wondering what difference does it make for having those TA's?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:17:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/host-is-not-being-extracted-from-linux-secure/m-p/432127#M95297</guid>
      <dc:creator>arsalanj</dc:creator>
      <dc:date>2020-09-30T00:17:25Z</dc:date>
    </item>
  </channel>
</rss>

