I am currently migrating to the cloud but struggling to get the data in the cloud correctly. I have a Kiwi sylog server and a forwarder that is getting the data to the cloud, but it shows up with the incorrect host and source type. I have edited the inputs.conf to fix the source type to syslog, and that changes the hostname from the ip address of the syslog server to the facility in the message. I just need it to go one tab to the right.
Any ideas? Below is an example of how the data is formatted when sent from Kiwi.
Yes I am actually doing that for my firewalls already and that works fine using host_segment. Was hoping to be able to leave all my switches in one location instead of making hundreds of directories. Its obviously expecting host where Kiwi puts facility. Havent found a way to change that on the Kiwi side yet so was hoping Splunk had something I was unaware of. Previously we sent everything direct to splunk when it was on prem but couldnt continue that when we went to splunk cloud. Thanks.