Souce name resolution OR change name of sources

(Rafaelcarsetimo) #1

I’m changing the names of the servers in our infrastructure, and I need the new names in graylog “source” field. I registered the names in /etc/hosts and I put the search for “files dns” in /etc/nsswitch.conf, and already created a entry A in my DNS, but the messages are still using the old source name. Can you guys give me a hint to force Graylog to use the hosts file to register the sources or another method? Can I rename Sources in Graylog?


Rafael Carvalho

(Jan Doberstein) #2

Hej @rafaelcarsetimo

you did not loose a word about how you ingest your messages. Because if you use syslog messages the sending Server will send his name and only if the sending server change the name this will be honored and displayed in Graylog.

Said that you can modify the source with pipelines (for example) and rewrite that.