Skip to main content
Solved

Remove Cribl Worker host field from message

  • March 11, 2025
  • 1 reply
  • 8 views

In a passthru route, Stream is adding the Cribl Worker ip address into the host field before sending to Splunk. How that can be avoided? This fields already comes from the source with different values.

Best answer by Eugene Katz

Is your source is syslog? Cribl will parse the syslog header and extract the host field. If youre looking for the ip of the sender, you can find that in __srcIpPort.

1 reply

Eugene Katz
  • Employee
  • Answer
  • March 11, 2025

Is your source is syslog? Cribl will parse the syslog header and extract the host field. If youre looking for the ip of the sender, you can find that in __srcIpPort.