Hi
I want to set different host value on udp 514 .
Events host values equals their IPs, so I want to change it to hostnames.
I configured the inputs.conf as below:
[udp://1.1.1.1:514]
host = SWITCH
connection_host = dns
sourcetype = syslog-Switch
[udp://2.2.2.2:514]
host = FIREWALL
connection_host = dns
sourcetype = syslog-FIREWALL
The sourcetype values change, but host values do not.
host
value to "SWITCH" or "FIREWALL", but also using connection_host = dns
. What is it that you want to achieve?If connection_host = dns
is not resulting in having hostnames in the host field, but still results in IP addresses, are you sure the IP address can be resolved to a hostname using a reversed DNS lookup?
Also: do you have any configuration in place that might override the host field value using information from inside the events?
I removed connection_host = dns
but result does not change.
as far as i checked, there was no configuration in place that override the host field value using events information.
I think the inputs.conf spec prescribes to set connection_host = none
if you want to set the host using a host =
setting.