We deploy code to Azure Cloud Apps and I have a script to re-write the host portion of the inputs.conf for the universal forwarder by adding the role name and deployment id. This means that we can track down logs to a particular instance if we need to.
However even when I override this value, the performance counter data that hits the indexer has the computer's name as the host instead of the value in inputs.conf.
How do I go about getting the right host text used? I'm not sure about changing the source type since it's set to Perfmon in Splunk and I assume that's a good thing.
... View more