As stated above, we have noticed that Splunk is setting the hostname index for syslog events to the value of the fromHost field. We need to be able to set it to the value contained in the HOSTNAME or fix the fromHost to not be localhost.
Does anyone ave any ideas as to how to fix this behavior?
You can also set the host field in inputs.conf but I've found that using props and transforms is more flexible.
http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf
You can setup custom index time transforms on the host meta field by configuring stanzas in props.conf and transforms.conf
A few answers similar to this on Splunkbase already.Here is a good link:
http://docs.splunk.com/Documentation/Splunk/latest/Data/overridedefaulthostassignments