I have several VM servers from an image. The host names have been changed but somewhere the old host name is populating the messages file. when I monitor the messages file on all the hosts they all have the same host name for that source
OCT 13 08:02:29 OLDHOST fprintd ** Message: No device in use, exit
Splunk sees this log as process fprintd coming from source "/var/log/messages" from host "OLDHOST" I have set the server.conf and the inputs.conf to the new host name but it is still pulling from the log file.
Ya, no, not a stupid question at all. I appreceate the responce. I did restart the client and I did use the btool to look for posable presedences of renaming the host = oldhostname. I don't know where this is comeing from or why splunk is pulling from the log file. maybe I will try changeing the source for the logs. Maybe becasue it is source = syslog it is pu;lling the host name from the log file.
Hi @cusello thanks for the info. I am useing a monitor stanza to watch the "var/log/..." folder All the other files in the folder are source=syslog. the only file I am haveing prolems with is the messages file. As I stated above with the log example the OldHostName is in the "messages" file and even though I put the [default] host = "NewHostName" in both the server.conf and the [monitor://] stanza in the inputs.conf. the other logs in the "/var/log/..." have the right host name tag on the logs just the messages have the oldhostname in the logs and is useing the oldhostname as the host tag.