Getting Data In

Will the Splunk server be able to parse the real IP address of the log source itself?

cutegirl
Engager

Hi community,

I am new to Splunk and considering to evaluate it as our enterprise log collection and SIEM setup.

If I want to forward logs to a Splunk forwarder and then it forwards to a Splunk server, will the splunk server be able to parse the real IP address of the log source itself? Or will it see the splunk forwarder IP as the real source IP?

We want to forward all our server logs to this splunk forwarder, and then to server. But being able to see real IP addresses is what we are concerned with.

 

thanks

 

Labels (2)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi @cutegirl,

how your logs are sent to the forwarder? are they syslogs?

If they are syslogs, the real IP is in the logs so it's possible to override the IP reading the IP inside the logs.

This job cand be done only on Indexers or (when present) on Heavy Forwarders.

Which kinf of Forwarders are you using?

If HF, you can do this overrding on the same machine, if instead you're using an Universal Forwarder, you have to do this job on an intermedate HF (if present) or in the Indexers.

The way to override host is described at https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments

In addition, I worked with other log collectors and SIEMs, I found Splunk as the best of them!

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
Esteemed Legend

Hi @cutegirl,

how your logs are sent to the forwarder? are they syslogs?

If they are syslogs, the real IP is in the logs so it's possible to override the IP reading the IP inside the logs.

This job cand be done only on Indexers or (when present) on Heavy Forwarders.

Which kinf of Forwarders are you using?

If HF, you can do this overrding on the same machine, if instead you're using an Universal Forwarder, you have to do this job on an intermedate HF (if present) or in the Indexers.

The way to override host is described at https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments

In addition, I worked with other log collectors and SIEMs, I found Splunk as the best of them!

Ciao.

Giuseppe

0 Karma

cutegirl
Engager

Thank you. I will take a look at the link

0 Karma

gcusello
Esteemed Legend

Hi @cutegirl,

tell me if we cal help you more, otherwise, please accept the answer for the other paople of Community.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma

cutegirl
Engager

Thank you. I have accepted the answer for now. Will come back if there are any other queries after my experimentation.

0 Karma
Get Updates on the Splunk Community!

Index This | A sphere has three, a circle has two, and a point has zero. What is it?

September 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...