<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog into Splunk, the host field contains the intercluster LIFs in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslog-into-Splunk-the-host-field-contains-the-intercluster-LIFs/m-p/140407#M31058</link>
    <description>&lt;P&gt;I'm starting to use Splunk to ingest amongst other things syslog from a number of FAS systems, running cDOT 9.1P5 atm.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As such, it works and I'm able to index and search the syslog data in Splunk. I'm still learning, but I noticed that the field "host" in Splunk resolves to the two Intercluser LIFs I have configured for SnapMirror/Vault replication to another FAS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd very much prefer if the host field was the cluster management LIF, or the node management LIFs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone with experience with the Splunk integration? I've not examined the raw syslog data yet, I've installed the Splunk Add-On for Netapp to get the "ontap:syslog" sourcetype and as I mentioned, I can see the basic flow of syslog data coming in.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 13:41:48 GMT</pubDate>
    <dc:creator>ChannelTapeFibre</dc:creator>
    <dc:date>2025-06-04T13:41:48Z</dc:date>
    <item>
      <title>Syslog into Splunk, the host field contains the intercluster LIFs</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslog-into-Splunk-the-host-field-contains-the-intercluster-LIFs/m-p/140407#M31058</link>
      <description>&lt;P&gt;I'm starting to use Splunk to ingest amongst other things syslog from a number of FAS systems, running cDOT 9.1P5 atm.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As such, it works and I'm able to index and search the syslog data in Splunk. I'm still learning, but I noticed that the field "host" in Splunk resolves to the two Intercluser LIFs I have configured for SnapMirror/Vault replication to another FAS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd very much prefer if the host field was the cluster management LIF, or the node management LIFs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone with experience with the Splunk integration? I've not examined the raw syslog data yet, I've installed the Splunk Add-On for Netapp to get the "ontap:syslog" sourcetype and as I mentioned, I can see the basic flow of syslog data coming in.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:41:48 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Syslog-into-Splunk-the-host-field-contains-the-intercluster-LIFs/m-p/140407#M31058</guid>
      <dc:creator>ChannelTapeFibre</dc:creator>
      <dc:date>2025-06-04T13:41:48Z</dc:date>
    </item>
  </channel>
</rss>

