Getting Data In

syslog host transform base on event

bambarit
Explorer

I have syslog server and installed HF,

when send logs from HF to indexer, the host is represent base on Event host,

can we extract new field for HF hostname?

1 Solution

thambisetty
SplunkTrust
SplunkTrust

@bambarit 

yes you can change on forwarder before you send logs to Indexer.

————————————
If this helps, give a like below.

View solution in original post

0 Karma

vikramyadav
Contributor

Hi @bambarit 

Yes you can change the name of host. Also you can extract new fields from HF.

 

-----------------------------------------

If this helps your like will be appreciated 🙂

bambarit
Explorer

can we just use transform from indexer?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

You can modify host value and you can have extra meta fields to hold information of hf if you wish to.

————————————
If this helps, give a like below.
0 Karma

bambarit
Explorer

do you mean host value in forwarder inputs?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@bambarit 

yes you can change on forwarder before you send logs to Indexer.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...