Hi All,
I have a UF which gets logs of syslog via UDP:514.
I am trying to set sourcetypes by hosts' IPs but i can't figure this out.
For example, for [host::192.168.0.1] I want to set source type of "wineventlog".
Note:
I don't have an option to separate the logs into different folders by host..
Thanks !
You can configure the syslog server with a different IP address for each sourcetype you wish to define. Each IP should write to its own file(s) and your monitor statement should establish the sourcetype.
Here is a link to a Splunk Blog that goes into detail about syslog architecture:
https://www.splunk.com/en_us/blog/tips-and-tricks/syslog-ng-and-hec-scalable-aggregated-data-collect...
and here is a link to the author's .conf presentation:
https://conf.splunk.com/files/2017/slides/to-hec-with-syslog-scalable-aggregated-data-collection-in-...
If you are only just getting started with syslog/Splunk, you should really consider a mature deployment like those suggested above.
As i mentioned in my question above, i don't have an option to separate the logs into different files.
I am well aware of this method but unfortunately it is not an option at the moment.
Thanks any way