Getting Data In

Host name not showing correctly

hartfoml
Motivator

I have several VM servers from an image. The host names have been changed but somewhere the old host name is populating the messages file. when I monitor the messages file on all the hosts they all have the same host name for that source

OCT 13 08:02:29 OLDHOST fprintd ** Message: No device in use, exit

Splunk sees this log as process fprintd coming from source "/var/log/messages" from host "OLDHOST" I have set the server.conf and the inputs.conf to the new host name but it is still pulling from the log file.

Any help would be great

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi hartfoml,
sorry for the stupid question: did you restarted Forwarder?

After restart check your Forwarder's configuration using btool:

./splunk cmd btool server list --debug > server.txt
./splunk cmd btool inputs list --debug > inputs.txt

Bye.
Giuseppe

0 Karma

hartfoml
Motivator

Ya, no, not a stupid question at all. I appreceate the responce. I did restart the client and I did use the btool to look for posable presedences of renaming the host = oldhostname. I don't know where this is comeing from or why splunk is pulling from the log file. maybe I will try changeing the source for the logs. Maybe becasue it is source = syslog it is pu;lling the host name from the log file.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi hartfoml,
receiving syslog and using a standard syslog parsing, usually hostname is read from the same log, is there the old hostname in your logs?
Bye.
Giuseppe

0 Karma

hartfoml
Motivator

Hi @cusello thanks for the info. I am useing a monitor stanza to watch the "var/log/..." folder All the other files in the folder are source=syslog. the only file I am haveing prolems with is the messages file. As I stated above with the log example the OldHostName is in the "messages" file and even though I put the [default] host = "NewHostName" in both the server.conf and the [monitor://] stanza in the inputs.conf. the other logs in the "/var/log/..." have the right host name tag on the logs just the messages have the oldhostname in the logs and is useing the oldhostname as the host tag.

this is very unusual.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!