I am using the universal forwarder to collect logs from docker hosts however when i see the docker containers it has collected logs from it only shows the shortened version of their docker container id. The universal forwarder is listed correctly but the rest are not. Does anyone know how to correct this?
The output looks like so:
Host Count Last Update
0c3344bac2fe Quick Report 76 11/6/16 4:55:30.000 AM
3708dc8f8aff Quick Report 4 11/6/16 4:55:30.000 AM
9efb179e4653 Quick Report 13 11/6/16 4:55:30.000 AM
a043ad123e05 Quick Report 5 11/6/16 4:55:30.000 AM
dcbb531a48a0 Quick Report 166 11/6/16 4:55:30.000 AM
e3a71cd5188e Quick Report 34 11/6/16 4:55:30.000 AM
f93768a45cba Quick Report 84 11/6/16 4:55:30.000 AM
splunkuniversalforwarder Quick Report 5,831 11/6/16 5:05:15.000 AM
As you can see above only splunkuniversalforwarder is named correctly.
... View more