Splunk Search

log hostname in metrics.log

datacenter
New Member

In a distributed deployment on the indexer in metrics.log there are logged 2 fields: sourceHost and sourceIp. In my setup they are identical. The IP is logged in both fields. What do I have to configure to log the hostname as well (on the universal forwarders I think)?

Tags (1)
0 Karma

datacenter
New Member

[tcpout: _9700]
server = :9700

[tcpout-server://:9700]

[tcpout]
defaultGroup = _9700
disabled = false

0 Karma

datacenter
New Member

Yes serverName is set to hostname in server.conf. We although set the hostname in inputs.conf (host = ).

0 Karma

MarioM
Motivator

what is in the UF outputs.conf?

0 Karma

MarioM
Motivator

Have you tried to modify the following in $SPLUNK_HOME/etc/system/local/server.conf :

[general]
serverName = <ascii string>
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...