Getting Data In

How can I locate the actual source of events?

zindain24
Path Finder

I have a sourcetype that has a non-descriptive host and a source defined (both appear to have been overwritten by stanzas in inputs.conf).

Was wondering how I could track this back to the originating system so I can change the configuration. Right now I have no idea where the events are coming from. They are definitely coming from a universal or heavy forwarder.

Thanks

0 Karma

bandit
Motivator

I would recommend including the sourcetype in your question. For example, if Splunk is monitoring a syslog feed, it will override the forwarder host name with the host name written in the log records.

If you are using deployment server, you should be able to find rules for monitoring your sourcetype under an app in SPLUNK_HOME/etc/deployment-apps on your deployment server. Then use the application name found under deployment-apps and reference against serverclass.conf to see where your monitoring rules are targeted to.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...