Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Add-on for Unix and Linux: Splunk ignoring host entry in inputs.conf. How do I fix this configuration?

$
0
0
I have a system that has a different system name from the desired name in the etc/system/local/inputs.conf. I'm using Splunk_TA_nix to pull the system logs. I believe the props/transforms is changing the host to reflect the host in the logs. I only need this 1 system to to use the host in the Splunk configuration. All other systems will have matching names and the TA will be fine. Is there anything that I can put in the default config (outside the app) that will prevent this behavior?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>