Security

source IP field

allenhau
Engager

Hello,

I am new to splunk and have not started the evaluation yet but wanted to ask this question that may be obvious.

Let's say Firewall-1 sends logs to splunk with the source IP defined as "src IP"
Firewall-2 sends logs to splunk with source IP defined as "source IP"

Would splunk automatically place it into a common filed? If so, what would that field be called? If splunk can't place it into a common field what would an admin have to do to accomplish that?

Tags (1)
0 Karma

arjunpkishore5
Motivator

Unless you explicitly override the "host" field, it'll be part of the metadata field "host"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...