Getting Data In

Is it possible to use an indexer's IP address for output on universal forwarder, but display the host name on the indexer?

splunkmasterfle
Path Finder

Hi,

Is there a way to use the IP address of the indexer on the universal forwarder but have the name of the host displayed on the indexer ??

Here is my configuration :

[tcpout]
defaultGroup = indexer-group

[tcpout:indexer-group]
maxQueueSize = auto
server = 172.44.23.114:9997

[tcpout-server://172.44.23.114:9997]

Meaning that on my index it would show "prod-log-server" (the hostname) instead of 172.44.23.114

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The indexer address used in outputs.conf is unrelated to any hosts set in inputs.conf (or overridden in transforms.conf... so yes, there is a way - nothing's in your way in fact.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...