Hi,
i have installed a light forwarder on one of my syslog server (B), forwarding to the main server where indexing is done. On the forwarder B i have set a different source type than "syslog" to create easier filters in the roles assigned to user.
My problem is that on the main server the host filed is allways set to the hostname of the Forwarder B instead extracting from the message,
If i set the sourcetype on the forwarder to "syslog" then the host field is extracted correctly.
Do i have to do host field extraction for this sourcetype as well? If yes how and where (props.conf, transform.conf)?
thanks