Getting Data In

Will the Splunk server be able to parse the real IP address of the log source itself?

cutegirl
Engager

Hi community,

I am new to Splunk and considering to evaluate it as our enterprise log collection and SIEM setup.

If I want to forward logs to a Splunk forwarder and then it forwards to a Splunk server, will the splunk server be able to parse the real IP address of the log source itself? Or will it see the splunk forwarder IP as the real source IP?

We want to forward all our server logs to this splunk forwarder, and then to server. But being able to see real IP addresses is what we are concerned with.

 

thanks

 

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @cutegirl,

how your logs are sent to the forwarder? are they syslogs?

If they are syslogs, the real IP is in the logs so it's possible to override the IP reading the IP inside the logs.

This job cand be done only on Indexers or (when present) on Heavy Forwarders.

Which kinf of Forwarders are you using?

If HF, you can do this overrding on the same machine, if instead you're using an Universal Forwarder, you have to do this job on an intermedate HF (if present) or in the Indexers.

The way to override host is described at https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments

In addition, I worked with other log collectors and SIEMs, I found Splunk as the best of them!

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cutegirl,

how your logs are sent to the forwarder? are they syslogs?

If they are syslogs, the real IP is in the logs so it's possible to override the IP reading the IP inside the logs.

This job cand be done only on Indexers or (when present) on Heavy Forwarders.

Which kinf of Forwarders are you using?

If HF, you can do this overrding on the same machine, if instead you're using an Universal Forwarder, you have to do this job on an intermedate HF (if present) or in the Indexers.

The way to override host is described at https://docs.splunk.com/Documentation/Splunk/latest/Data/Overridedefaulthostassignments

In addition, I worked with other log collectors and SIEMs, I found Splunk as the best of them!

Ciao.

Giuseppe

0 Karma

cutegirl
Engager

Thank you. I will take a look at the link

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @cutegirl,

tell me if we cal help you more, otherwise, please accept the answer for the other paople of Community.

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated by all the Contributors 😉

0 Karma

cutegirl
Engager

Thank you. I have accepted the answer for now. Will come back if there are any other queries after my experimentation.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...