I have different devices sending data via syslog.
Current Stanza Example:
[udp//IP:PORT]
host = hostname
sourcetype = syslog
However, events still show up as host = ip address. Is there another place to do this?
It seems that the process is not as straight forward as I thought for syslog devices.
See this blog post:
http://blogs.splunk.com/2008/04/16/overriding-default-syslog-host-extraction/
Now trying to figure out how to do this in a Cluster.
I had the same problem, even if I told it not to. It sorta double dips your hostnames, especially if you already had the hostname show up prior to enabling syslog.