Hi I've recently installed Splunk and have set up a couple of our test ESX host to forward syslog data to the Splunk server and they are forwarding the data but under hosts the entry is showing IP address and not DNS name.
The UDP input is set to DNS and the inputs.conf file shows connection_hosts = DNS.
How can i get the Hosts to show DNS name and not IP?
Version is 4.1.6-89596.
Cheers
Is the entry connection_hosts
or is is connection_host
? The latter is correct. Is the value DNS
or is it dns
? Again, the latter is correct. Both of these settings must be correct for this to work.
from the inputs.conf file:
connection_host = dns
I believe that the connection_hosts
attribute is reserved for the TCP input only.
http://www.splunk.com/base/Documentation/4.1.6/Admin/Inputsconf