Getting Data In

Windows Logs src_ip field

adrianathome
Communicator

Is there a way to add the src_ip Field to windows events?

Looking for options that do not involve a lookup.

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You mean you want to collect and add it to the log events at the time of capture? If so, then short of writing your own input (or modifying the Splunk one) on the forwarder, I can not think of one.

0 Karma

adrianathome
Communicator

Have you ever seen anybody setting the host=ip on inputs.conf? I wonder if the events themselves always have the hostname or computer name value in them and we can add the IP address via inputs.conf.

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...