Getting Data In

Will the Splunk server be able to parse the real IP address of the log source itself?

cutegirl
Engager

Hi community,

I am new to Splunk and considering to evaluate it as our enterprise log collection and SIEM setup.

If I want to forward logs to a Splunk forwarder and then it forwards to a Splunk server, will the splunk server be able to parse the real IP address of the log source itself? Or will it see the splunk forwarder IP as the real source IP?

We want to forward all our server logs to this splunk forwarder, and then to server. But being able to see real IP addresses is what we are concerned with.

 

thanks

 

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @cutegirl,

how your logs are sent to the forwarder? are they syslogs?

If they are syslogs, the real IP is in the logs so it's possible to override the IP reading the IP inside the logs.

This job cand be done only on Indexers or (when present) on Heavy Forwarders.

Which kinf of Forwarders are you using?

If HF, you can do this overrding on the same machine, if instead you're using an Universal Forwarder, you have to do this job on an intermedate HF (if present) or in the Indexers.

The way to override host is described at https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments

In addition, I worked with other log collectors and SIEMs, I found Splunk as the best of them!

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cutegirl,

how your logs are sent to the forwarder? are they syslogs?

If they are syslogs, the real IP is in the logs so it's possible to override the IP reading the IP inside the logs.

This job cand be done only on Indexers or (when present) on Heavy Forwarders.

Which kinf of Forwarders are you using?

If HF, you can do this overrding on the same machine, if instead you're using an Universal Forwarder, you have to do this job on an intermedate HF (if present) or in the Indexers.

The way to override host is described at https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments

In addition, I worked with other log collectors and SIEMs, I found Splunk as the best of them!

Ciao.

Giuseppe

0 Karma

cutegirl
Engager

Thank you. I will take a look at the link

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cutegirl,

tell me if we cal help you more, otherwise, please accept the answer for the other paople of Community.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma

cutegirl
Engager

Thank you. I have accepted the answer for now. Will come back if there are any other queries after my experimentation.

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...