Skip to content

Commit

Permalink
Merge pull request #438 from splunk/feature/rdns
Browse files Browse the repository at this point in the history
Support reverse DNS
  • Loading branch information
Ryan Faircloth authored and GitHub committed May 7, 2020
2 parents d5564a3 + cd54a71 commit 9085ed4
Show file tree
Hide file tree
Showing 3 changed files with 6 additions and 5 deletions.
1 change: 1 addition & 0 deletions docs/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ and variables needed to properly configure SC4S for your environment.
|----------|---------------|-------------|
| SPLUNK_HEC_URL | url | URL(s) of the Splunk endpoint, can be a single URL space seperated list |
| SPLUNK_HEC_TOKEN | string | Splunk HTTP Event Collector Token |
| SC4S_GLOBAL_DNS_USE | yes or no(default) | use reverse DNS to identify hosts when HOST is not valid in the syslog header |

* NOTE: Do _not_ configure HEC Acknowledgement when deploying the HEC token on the Splunk side; the underlying syslog-ng http
destination does not support this feature. Moreover, HEC Ack would significantly degrade performance for streaming data such as
Expand Down
2 changes: 1 addition & 1 deletion package/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ COPY --from=hairyhenderson/gomplate:v3.5.0 /gomplate /usr/local/bin/gomplate

COPY goss.yaml goss.yaml

COPY etc/syslog-ng.conf /opt/syslog-ng/etc/syslog-ng.conf
COPY etc/syslog-ng.conf.tmpl /opt/syslog-ng/etc/syslog-ng.conf.tmpl
COPY etc/conf.d /opt/syslog-ng/etc/conf.d
COPY etc/go_templates /opt/syslog-ng/etc/go_templates
COPY etc/context_templates /opt/syslog-ng/etc/context_templates
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,12 +17,12 @@ options {
flush_lines (100);
time_reopen (10);
log_fifo_size (10000);
chain_hostnames (off);
use_dns (no);
chain_hostnames (yes);
use_dns ({{getenv "SC4S_GLOBAL_DNS_USE" "no"}});
use_fqdn (no);
dns-cache(no);
dns-cache({{getenv "SC4S_GLOBAL_DNS_CACHE" "yes"}});
create_dirs (no);
keep-hostname (yes);
keep-hostname (no);
create_dirs(yes);
dir_perm(0750);
stats-freq(30);
Expand Down

0 comments on commit 9085ed4

Please sign in to comment.