Getting Data In

Is it possible to configure an app in Splunk to overwrite the hostname in logs sent from a universal forwarder?

mlhess
New Member

Hi all,

New to Splunk here. I have configured 100 servers to send syslog data. I did this by using puppet to install the universal forwarder, and set a deployment server address to my Splunk server, then in Splunk, I built an app to send syslog data back (using inputs.conf and outputs.conf). The app gets deployed.

I now have syslog data in my Splunk install!

However, given some history on some of these servers, I am getting multiple hostnames per server. (mostly abc and abc.domain.com)

Can I configure Splunk to overwrite the hostname from the logs?

In inputs.conf I tried to add

host=

However that did not seem to work.

0 Karma

renems
Communicator

Hi There,

Check this out, here's the answer to your question: https://answers.splunk.com/answers/45899/how-can-i-use-the-fully-qualified-domain-name-fqdn-as-the-h...

Enjoy!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...