0 Replies Latest reply on Sep 17, 2018 7:08 AM by Bpfoley

    Windows Event Collector Parsing

    Bpfoley Lurker

      I would like to ship events from windows event collector into Log Insight, everything appears to be working- however the hostname field is that of the collector server- not of the forwarded events. I validated that this information is intact within the raw windows event source under the <System>, <Computer> section.

       

      Is there a way to configure the agent to read hostname from the log rather than override with the sender hostname?