Installation

Can you help me rewrite the hostname of syslog data being sent to SplunkCloud?

dyhorner
Engager

I am currently migrating to the cloud but struggling to get the data in the cloud correctly. I have a Kiwi sylog server and a forwarder that is getting the data to the cloud, but it shows up with the incorrect host and source type. I have edited the inputs.conf to fix the source type to syslog, and that changes the hostname from the ip address of the syslog server to the facility in the message. I just need it to go one tab to the right.

Any ideas? Below is an example of how the data is formatted when sent from Kiwi.

2018-11-06 16:20:23 Local7.Notice   10.1.111.1  
Labels (1)
Tags (2)

bcyates
Communicator

Are you writing the hostname to the directory where logs are being written in Kiwi?

For example, C:\Program Files\Kiwi\firewall\HOSTNAME\ logfile.txt

If so, you can set host_segment in your inputs.conf.

In my example, your host_segment would be 4. So it would take the 4th entry from your path and make that the hostname

0 Karma

dyhorner
Engager

Yes I am actually doing that for my firewalls already and that works fine using host_segment. Was hoping to be able to leave all my switches in one location instead of making hundreds of directories. Its obviously expecting host where Kiwi puts facility. Havent found a way to change that on the Kiwi side yet so was hoping Splunk had something I was unaware of. Previously we sent everything direct to splunk when it was on prem but couldnt continue that when we went to splunk cloud. Thanks.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...