Getting Data In

syslog host transform base on event

bambarit
Explorer

I have syslog server and installed HF,

when send logs from HF to indexer, the host is represent base on Event host,

can we extract new field for HF hostname?

1 Solution

thambisetty
SplunkTrust
SplunkTrust

@bambarit 

yes you can change on forwarder before you send logs to Indexer.

————————————
If this helps, give a like below.

View solution in original post

0 Karma

vikramyadav
Contributor

Hi @bambarit 

Yes you can change the name of host. Also you can extract new fields from HF.

 

-----------------------------------------

If this helps your like will be appreciated 🙂

bambarit
Explorer

can we just use transform from indexer?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

You can modify host value and you can have extra meta fields to hold information of hf if you wish to.

————————————
If this helps, give a like below.
0 Karma

bambarit
Explorer

do you mean host value in forwarder inputs?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@bambarit 

yes you can change on forwarder before you send logs to Indexer.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...