Getting Data In

Hostname macro in inputs.conf

afx
Contributor

Hi,
I have a Linux based application server that exists in two copies on xhostA and xhostB.
I am getting their syslog output via a localhost syslog interface into the UF which is installed on those hosts.

I do not want to push individual inputs.conf files. So how to I get the appropriate host name for the syslog input?
If I leave host emtpy, I get 127.0.0.1 which is not helpful. When I set the hostname, it then is identical for both systems.

[udp://127.0.0.1:8514]
connection_host = 127.0.0.1
sourcetype=linux_secure
no_appending_timestamp = true
index= xauth

Any ideas on how to rectify this easily?
I assume that

host=$decideOnStartup

would just deliver 127.0.0.1 as leaving host empty results in this.

thx
afx

0 Karma
1 Solution

afx
Contributor

Ok, to answer my own question...
In contrast to what I assumed, $decideOnStartup is resolved to the real hostname and not the referenced address of the input like the default for host.

View solution in original post

0 Karma

afx
Contributor

Ok, to answer my own question...
In contrast to what I assumed, $decideOnStartup is resolved to the real hostname and not the referenced address of the input like the default for host.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...