Getting Data In

Assigning sourcetype by host - UF

astatrial
Contributor

Hi All,

I have a UF which gets logs of syslog via UDP:514.
I am trying to set sourcetypes by hosts' IPs but i can't figure this out.

For example, for [host::192.168.0.1] I want to set source type of "wineventlog".

Note:
I don't have an option to separate the logs into different folders by host..

Thanks !

0 Karma

mydog8it
Builder

You can configure the syslog server with a different IP address for each sourcetype you wish to define. Each IP should write to its own file(s) and your monitor statement should establish the sourcetype.

Here is a link to a Splunk Blog that goes into detail about syslog architecture:
https://www.splunk.com/en_us/blog/tips-and-tricks/syslog-ng-and-hec-scalable-aggregated-data-collect...
and here is a link to the author's .conf presentation:
https://conf.splunk.com/files/2017/slides/to-hec-with-syslog-scalable-aggregated-data-collection-in-...

If you are only just getting started with syslog/Splunk, you should really consider a mature deployment like those suggested above.

0 Karma

astatrial
Contributor

As i mentioned in my question above, i don't have an option to separate the logs into different files.
I am well aware of this method but unfortunately it is not an option at the moment.

Thanks any way

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...