<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding domain name to hostnames in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28981#M177882</link>
    <description>&lt;P&gt;and have a few quesions, &lt;BR /&gt;
first, can this be debuged somehow ? &lt;BR /&gt;
or log showing whats happening ? &lt;BR /&gt;
also, why do the entries  inside [] dont match ? should they ?&lt;/P&gt;</description>
    <pubDate>Sun, 15 Aug 2010 23:29:05 GMT</pubDate>
    <dc:creator>msupino</dc:creator>
    <dc:date>2010-08-15T23:29:05Z</dc:date>
    <item>
      <title>Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28970#M177871</link>
      <description>&lt;P&gt;I have multiple LightForwarded, in different domains, who have similar host names (machines inside one domain are the same as machines in another domain),&lt;/P&gt;

&lt;P&gt;how can i configure each splunk LightForwarder to add the domain name of any event it sends to the Central splunk ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2010 19:04:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28970#M177871</guid>
      <dc:creator>msupino</dc:creator>
      <dc:date>2010-08-12T19:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28971#M177872</link>
      <description>&lt;P&gt;You can edit the hostname assigned to events from a host by editing the host= value in your &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/inputs.conf&lt;/CODE&gt;. Just change it from &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=hostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;to &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=hostname.domain.com
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 12 Aug 2010 22:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28971#M177872</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-08-12T22:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28972#M177873</link>
      <description>&lt;P&gt;this will change the local events, but events from the syslog, for example, will not be changed by this, which is fine, as they might come from other machines in the same domain.&lt;/P&gt;

&lt;P&gt;so, i want to add .something.com to all hostname evetns, is that possible somehow ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2010 23:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28972#M177873</guid>
      <dc:creator>msupino</dc:creator>
      <dc:date>2010-08-12T23:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28973#M177874</link>
      <description>&lt;P&gt;I'm sorry, but i'm not sure what you're trying to get at here. Your question indicated you're using a forwarder setup rather than syslog. How are you sending your syslog to splunk? Via a direct network input in splunk or via syslog-ng and then indexing the resulting logs?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2010 00:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28973#M177874</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-08-13T00:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28974#M177875</link>
      <description>&lt;P&gt;syslog has info from local and remove machines&lt;/P&gt;

&lt;P&gt;the *nix app is fixed by host= entry&lt;BR /&gt;
but, the same host writes things to syslog,and other nodes writes to syslog through syslogd, these entires dont have the domaine, for example, &lt;/P&gt;

&lt;P&gt;Aug 12 14:20:06 xen00 last message repeated 3 times&lt;BR /&gt;
this doesnt have the domain name, so the same machine, from different SplunkLightForwarders in different locations will be indexed under the same hostname.&lt;/P&gt;

&lt;P&gt;i want splunk in each location to add a domain name to the hostname it sees in syslog.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2010 01:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28974#M177875</guid>
      <dc:creator>msupino</dc:creator>
      <dc:date>2010-08-13T01:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28975#M177876</link>
      <description>&lt;P&gt;just to be clear, *nix is parsing /var/log/syslog&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2010 01:22:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28975#M177876</guid>
      <dc:creator>msupino</dc:creator>
      <dc:date>2010-08-13T01:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28976#M177877</link>
      <description>&lt;P&gt;I recommend using a transformer for adding a static domain name to your &lt;CODE&gt;host&lt;/CODE&gt; field.  I've previously posted some config examples (linke below) that works for the syslog (and various derived) sourcetypes.  The example shown is smart enough not to accidentally append your domain to an IP address.&lt;/P&gt;

&lt;P&gt;Please see my answer here:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://answers.splunk.com/questions/1673/hostname-rename-using-transforms/1686#1686" rel="nofollow"&gt;hostname rename using TRANSFORMS&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 13 Aug 2010 22:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28976#M177877</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-13T22:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28977#M177878</link>
      <description>&lt;P&gt;Splunk has a transformer that extracts "host" from syslog sourcetypes, and that will  override any given &lt;CODE&gt;host=myhostname&lt;/CODE&gt; that you setup in &lt;CODE&gt;inputs.conf&lt;/CODE&gt;.  Just for the record, I do think setting your hostname in this way is also a good idea, but I suggest doing so at the top of &lt;CODE&gt;system/local/inputs.conf&lt;/CODE&gt; (as ftk suggests) rather than in the &lt;CODE&gt;unix&lt;/CODE&gt; app--this way the setting is fully global and not limited to a single app context.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2010 22:16:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28977#M177878</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-13T22:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28978#M177879</link>
      <description>&lt;P&gt;will this work on a LightForwarder ?&lt;/P&gt;</description>
      <pubDate>Sat, 14 Aug 2010 01:13:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28978#M177879</guid>
      <dc:creator>msupino</dc:creator>
      <dc:date>2010-08-14T01:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28979#M177880</link>
      <description>&lt;P&gt;I'm not 100% sure, you can try it.  Worst case scenario is that you have to put it on the indexer.  I think this also depends on your Splunk version, I think 4.0 does more on light forwarder than was handled by the 3.x light forwarders.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Aug 2010 04:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28979#M177880</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-14T04:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28980#M177881</link>
      <description>&lt;P&gt;i looked at the example above, and see :&lt;/P&gt;

&lt;P&gt;[syslog_add_mfpsdotcom]&lt;BR /&gt;
DEST_KEY = MetaData:Host&lt;BR /&gt;
SOURCE_KEY = MetaData:Host&lt;BR /&gt;
REGEX    = host::([A-Za-z][-_A-Za-z0-9]*[A-Za-z0-9])$&lt;BR /&gt;
FORMAT   = host::$1.my-domain-name.com&lt;/P&gt;

&lt;P&gt;[syslog]&lt;BR /&gt;
TRANSFORMS-zz_fix_host = syslog_add_fqdn&lt;/P&gt;

&lt;P&gt;[linux_messages_syslog]&lt;BR /&gt;
TRANSFORMS-zz_fix_host = syslog_add_fqdn&lt;/P&gt;

&lt;P&gt;[linux_secure]&lt;BR /&gt;
TRANSFORMS-zz_fix_host = syslog_add_fqdn&lt;/P&gt;

&lt;P&gt;[postfix_syslog]&lt;BR /&gt;
TRANSFORMS-zz_fix_host = syslog_add_fqdn&lt;/P&gt;

&lt;P&gt;[sendmail_syslog]&lt;BR /&gt;
TRANSFORMS-zz_fix_host = syslog_add_fqdn&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:15:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28980#M177881</guid>
      <dc:creator>msupino</dc:creator>
      <dc:date>2020-09-28T09:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28981#M177882</link>
      <description>&lt;P&gt;and have a few quesions, &lt;BR /&gt;
first, can this be debuged somehow ? &lt;BR /&gt;
or log showing whats happening ? &lt;BR /&gt;
also, why do the entries  inside [] dont match ? should they ?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Aug 2010 23:29:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28981#M177882</guid>
      <dc:creator>msupino</dc:creator>
      <dc:date>2010-08-15T23:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28982#M177883</link>
      <description>&lt;P&gt;Note that I had a typo on that page, which has been fixed now.  The transformer should have been named &lt;CODE&gt;syslog_add_fqdn&lt;/CODE&gt;.  Hopefully that was obvious from the context, but it was a mistake which has been corrected now.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2010 20:04:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28982#M177883</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-16T20:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Adding domain name to hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28983#M177884</link>
      <description>&lt;P&gt;I don't know of any way to really "debug" this type of activity other than to actually try it.  Hopefully fixing the transformer name will resolve the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2010 20:08:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Adding-domain-name-to-hostnames/m-p/28983#M177884</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-08-16T20:08:36Z</dc:date>
    </item>
  </channel>
</rss>

