Getting Data In

Is it possible to configure an app in Splunk to overwrite the hostname in logs sent from a universal forwarder?

mlhess
New Member

Hi all,

New to Splunk here. I have configured 100 servers to send syslog data. I did this by using puppet to install the universal forwarder, and set a deployment server address to my Splunk server, then in Splunk, I built an app to send syslog data back (using inputs.conf and outputs.conf). The app gets deployed.

I now have syslog data in my Splunk install!

However, given some history on some of these servers, I am getting multiple hostnames per server. (mostly abc and abc.domain.com)

Can I configure Splunk to overwrite the hostname from the logs?

In inputs.conf I tried to add

host=

However that did not seem to work.

0 Karma

renems
Communicator

Hi There,

Check this out, here's the answer to your question: https://answers.splunk.com/answers/45899/how-can-i-use-the-fully-qualified-domain-name-fqdn-as-the-h...

Enjoy!

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...