<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Determine Source IP of log entry in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Determine-Source-IP-of-log-entry/m-p/235610#M7955</link>
    <description>&lt;P&gt;I have log entries that are appearing in Splunk that are being labeled as coming from a specific host, but that host isn't even turned on.&lt;/P&gt;

&lt;P&gt;How can I view the origin IP of a log entry regardless of the host label?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2016 22:35:56 GMT</pubDate>
    <dc:creator>jwilson_clover</dc:creator>
    <dc:date>2016-03-07T22:35:56Z</dc:date>
    <item>
      <title>Determine Source IP of log entry</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Determine-Source-IP-of-log-entry/m-p/235610#M7955</link>
      <description>&lt;P&gt;I have log entries that are appearing in Splunk that are being labeled as coming from a specific host, but that host isn't even turned on.&lt;/P&gt;

&lt;P&gt;How can I view the origin IP of a log entry regardless of the host label?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 22:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Determine-Source-IP-of-log-entry/m-p/235610#M7955</guid>
      <dc:creator>jwilson_clover</dc:creator>
      <dc:date>2016-03-07T22:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Determine Source IP of log entry</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Determine-Source-IP-of-log-entry/m-p/235611#M7956</link>
      <description>&lt;P&gt;This is not possible. The only metadata associated to any particular event (by default) is: host, sourcetype, source, and index. You could create a new indexed field extraction to identify the origin IP, or apply a transformation to the host field, but you have to configure it, and it will only be applied to future events.&lt;/P&gt;

&lt;P&gt;You might also consider setting the host field to the desired value(s) in inputs.conf for each input stanza on your forwarder(s).&lt;/P&gt;

&lt;P&gt;See:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Configureindex-timefieldextraction"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Configureindex-timefieldextraction&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Data/Overridedefaulthostassignments"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Data/Overridedefaulthostassignments&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 23:22:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Determine-Source-IP-of-log-entry/m-p/235611#M7956</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2016-03-07T23:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Determine Source IP of log entry</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Determine-Source-IP-of-log-entry/m-p/235612#M7957</link>
      <description>&lt;P&gt;All the hosts have that set, yet this mysterious entry keeps appearing.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 00:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Determine-Source-IP-of-log-entry/m-p/235612#M7957</guid>
      <dc:creator>jwilson_clover</dc:creator>
      <dc:date>2016-03-08T00:20:18Z</dc:date>
    </item>
  </channel>
</rss>

