Microsoft Entra Suite Tech Accelerator
Aug 14 2024, 07:00 AM - 09:30 AM (PDT)
Microsoft Tech Community
SOLVED

Rsyslog Linux Machine to Sentinel

Brass Contributor

Hi All, we implement two Linux machine, one for collect log and send it to Microsoft Sentinel and another machine that send log from syslog to this collector, all works fine log sent correctly to Sentinel, but from host to Sentinel view Only Hostname but not Host IP, we have modify rsyslog.conf to modify template and send IP but not hsotname, there is a way to send both Host ip and hostname ?

 

Many Thanks,

Regard,

Guido

2 Replies
best response confirmed by gaudium91 (Brass Contributor)
Solution
Hello Guido,

I believe the Host IP is obtained via DNS lookup. A log collector agent (either LAA/MMA or AMA) will try to resolve the hostname within the syslog event using its hosts DNS configuration (usually configured within /etc/resolv.conf. Make sure the required search domains have been configured, and the hostname matches a record within your DNS server.

Regards,
Arjan
Thanks a lot smid, i modify dns configuration in this file and resolve my issue :)

Many Thanks,

Guido
1 best response

Accepted Solutions
best response confirmed by gaudium91 (Brass Contributor)
Solution
Hello Guido,

I believe the Host IP is obtained via DNS lookup. A log collector agent (either LAA/MMA or AMA) will try to resolve the hostname within the syslog event using its hosts DNS configuration (usually configured within /etc/resolv.conf. Make sure the required search domains have been configured, and the hostname matches a record within your DNS server.

Regards,
Arjan

View solution in original post