On our DNS server one of my machines has two A records, and two corresponding PTR records.
ie: server1 = 10.10.10.1 server001 = 10.10.10.1 This causes Graylog to treat this server as two different sources, it splits all input from that collector 50/50, some log entries show as source "server1" some show source "server001". Apparently these double entries are required for one of our apps. Without making any DNS changes, is there a way I can tell Graylog that anything gl2_remote_ip=10.10.10.1 should show as source "server1" ? Is there some kind of "hosts file" I can use to override DNS lookups? Thanks in advance, Dennis -- You received this message because you are subscribed to the Google Groups "Graylog Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/graylog2/420e6e5a-76bf-4468-8ec0-325259a257e7%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
