Hello,
System type: Linux
We have splunk running on our centralized syslog-ng server. We then have other servers forwarding syslog traffic to it. Those logs are then stored in their own folder based on their hostname (i.e. /var/log/syslog-ng/remoteHost/logfile.)
We have splunk setup to see the syslog-ng folder and it reads everything fine. But in splunk, the output of all the logs say host=localServerName, what I would like them to do is say host=remoteServerName, is this possible?
Thanks in advance for any suggestions.
... View more