Getting Data In

Is it possible to use an indexer's IP address for output on universal forwarder, but display the host name on the indexer?

splunkmasterfle
Path Finder

Hi,

Is there a way to use the IP address of the indexer on the universal forwarder but have the name of the host displayed on the indexer ??

Here is my configuration :

[tcpout]
defaultGroup = indexer-group

[tcpout:indexer-group]
maxQueueSize = auto
server = 172.44.23.114:9997

[tcpout-server://172.44.23.114:9997]

Meaning that on my index it would show "prod-log-server" (the hostname) instead of 172.44.23.114

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The indexer address used in outputs.conf is unrelated to any hosts set in inputs.conf (or overridden in transforms.conf... so yes, there is a way - nothing's in your way in fact.

Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...