AIX log ingestion issue

New Contributor

I am sending AIX logs to a central rsyslog server and using the Syslog Connector to pull the logs into Azure Sentinel. The ComputerName field is populating as `Message` and not the actual hostname or IP of the system. Anyone have thoughts on how to fix this?

2 Replies

Long story short, AIX adds a "Message forwarded by $hostname" string. You have to start syslogd on AIX with the flags:

startsrc -a -n -s syslogd

same issue i am facing.
@ackmysyn, i did as you suggested but still hostname ip address is not coming in logs.
any help will be highly appreciated