I have a system that has a different system name from the desired name in the etc/system/local/inputs.conf. I'm using Splunk_TA_nix to pull the system logs. I believe the props/transforms is changing the host to reflect the host in the logs. I only need this 1 system to to use the host in the Splunk configuration. All other systems will have matching names and the TA will be fine. Is there anything that I can put in the default config (outside the app) that will prevent this behavior?
↧