Getting Data In

Hostname macro in inputs.conf

afx
Contributor

Hi,
I have a Linux based application server that exists in two copies on xhostA and xhostB.
I am getting their syslog output via a localhost syslog interface into the UF which is installed on those hosts.

I do not want to push individual inputs.conf files. So how to I get the appropriate host name for the syslog input?
If I leave host emtpy, I get 127.0.0.1 which is not helpful. When I set the hostname, it then is identical for both systems.

[udp://127.0.0.1:8514]
connection_host = 127.0.0.1
sourcetype=linux_secure
no_appending_timestamp = true
index= xauth

Any ideas on how to rectify this easily?
I assume that

host=$decideOnStartup

would just deliver 127.0.0.1 as leaving host empty results in this.

thx
afx

0 Karma
1 Solution

afx
Contributor

Ok, to answer my own question...
In contrast to what I assumed, $decideOnStartup is resolved to the real hostname and not the referenced address of the input like the default for host.

View solution in original post

0 Karma

afx
Contributor

Ok, to answer my own question...
In contrast to what I assumed, $decideOnStartup is resolved to the real hostname and not the referenced address of the input like the default for host.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...