Getting Data In
Highlighted

Why am I seeing duplicate field values under interesting fields?

Explorer

Can anyone tell my why I am see duplicate host values (1 uppercase and 1 lowercase) in my interesting fields and how to fix it. I have checked inputs.conf and server.conf, they both show the uppercase version. I am not sure where this second host name is originating from.

alt text

0 Karma
Highlighted

Re: Why am I seeing duplicate field values under interesting fields?

Legend

@cc3658 check the source and also sourcetype for the two hosts.




| eval message="Happy Splunking!!!"


0 Karma
Highlighted

Re: Why am I seeing duplicate field values under interesting fields?

Champion

If the sourcetype is syslog, the syslog-host transform will set the hostname based on the value in the event itself.

For the events that have the unexpected host value, what is the sourcetype, and can you paste the _raw values for them as well?

0 Karma
Highlighted

Re: Why am I seeing duplicate field values under interesting fields?

Explorer

Yes, the sourcetype is syslog. How would I correct it? A change to the syslog-host transform or a conf file on the host itself? Thanks!

0 Karma
Highlighted

Re: Why am I seeing duplicate field values under interesting fields?

SplunkTrust
SplunkTrust

yes, you can override in transforms.conf with the values you want or you can use a regex to extract from the event.
[yoursourcetype]
REGEX = (.+)
DESTKEY = MetaData:Host
FORMAT = host:my
host

0 Karma