Getting Data In

Setting host to hostname vs IP address

agodoy
Communicator

I have different devices sending data via syslog.

Current Stanza Example:

[udp//IP:PORT]
host = hostname
sourcetype = syslog

However, events still show up as host = ip address. Is there another place to do this?

Tags (2)
0 Karma

agodoy
Communicator

It seems that the process is not as straight forward as I thought for syslog devices.

See this blog post:

http://blogs.splunk.com/2008/04/16/overriding-default-syslog-host-extraction/

Now trying to figure out how to do this in a Cluster.

0 Karma

gnovak
Builder

I had the same problem, even if I told it not to. It sorta double dips your hostnames, especially if you already had the hostname show up prior to enabling syslog.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...