Getting Data In

How to set host in inputs.conf?

plj3736
New Member

I'm getting data in syslog format with the host set to localhost. I know what server this is coming from but don't have authority to change the hostname at the server. The data is being put into a directory on my local server, not through UDP or TCP transfer. Here's what I have in inputs.conf

[monitor:///home/Analysis/tc-1/server1/*.gz]
index=tc-1
host=server1
disabled=false

I've tried this both with and without sourcetype=syslog as added input here. A few of the records come in as host of server1 but most have localhost listed as the source. Any help would be appreciated.

Tags (2)
0 Karma

plj3736
New Member

I don't want to extract the hostname from the syslog event, the hostname is localhost and it's not correct. I know the event came from a specific server so I'm trying to replace the hostname with the specific server name. Putting host=server1 in inputs.conf changes some of the records but not all. What can I do to change all of them.

0 Karma

plj3736
New Member

I don't want to extract the hostname from the syslog event, the hostname is localhost and it's not correct. I know the event came from a specific server so I'm trying to replace the hostname with the specific server name. Putting host=server1 in inputs.conf changes some of the records but not all. What can I do to change all of them.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Splunk automatically extracts the host from syslog events, overwriting the setting from inputs.conf because usually the event is more accurate than using the central syslog daemon's host.

To avoid that happening to your events you could set a different sourcetype than syslog.

0 Karma

linu1988
Champion

you cant change them now, you need to delete them all and re-index if you require single host name.

0 Karma

plj3736
New Member

I don't want to extract the hostname from the syslog event, the hostname is localhost and it's not correct. I know the event came from a specific server so I'm trying to replace the hostname with the specific server name. Putting host=server1 in inputs.conf changes some of the records but not all. What can I do to change all of them.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...