Rsyslog logs display short hostname instead of FQDN, causing hostname conflicts in Centralized log server.
Issue
- Syslog is sending logs based on the short hostname, causing conflicts when multiple servers have the same short name.
- For instance, servers with hostnames
server.example.comandserver.lab.example.comboth send logs under the short nameserver. - This behavior causes confusion when reviewing logs in a SIEM system, especially when multiple servers share the same short hostname.
- It's difficult to differentiate between logs from different servers in a centralized logging environment.
Environment
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux 10
- Centralized logging setup with logs forwarded to SIEM or remote rsyslog server
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.