Getting Data In

syslog host transform base on event

bambarit
Explorer

I have syslog server and installed HF,

when send logs from HF to indexer, the host is represent base on Event host,

can we extract new field for HF hostname?

1 Solution

thambisetty
SplunkTrust
SplunkTrust

@bambarit 

yes you can change on forwarder before you send logs to Indexer.

————————————
If this helps, give a like below.

View solution in original post

0 Karma

vikramyadav
Contributor

Hi @bambarit 

Yes you can change the name of host. Also you can extract new fields from HF.

 

-----------------------------------------

If this helps your like will be appreciated 🙂

bambarit
Explorer

can we just use transform from indexer?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

You can modify host value and you can have extra meta fields to hold information of hf if you wish to.

————————————
If this helps, give a like below.
0 Karma

bambarit
Explorer

do you mean host value in forwarder inputs?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@bambarit 

yes you can change on forwarder before you send logs to Indexer.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...