Splunk Search

log hostname in metrics.log

datacenter
New Member

In a distributed deployment on the indexer in metrics.log there are logged 2 fields: sourceHost and sourceIp. In my setup they are identical. The IP is logged in both fields. What do I have to configure to log the hostname as well (on the universal forwarders I think)?

Tags (1)
0 Karma

datacenter
New Member

[tcpout: _9700]
server = :9700

[tcpout-server://:9700]

[tcpout]
defaultGroup = _9700
disabled = false

0 Karma

datacenter
New Member

Yes serverName is set to hostname in server.conf. We although set the hostname in inputs.conf (host = ).

0 Karma

MarioM
Motivator

what is in the UF outputs.conf?

0 Karma

MarioM
Motivator

Have you tried to modify the following in $SPLUNK_HOME/etc/system/local/server.conf :

[general]
serverName = <ascii string>
0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...