Greetings,
is there a setup where Sagan would include the hostname in alerts or log events? SyslogNG can seem to use hostnames in the pipe to Sagan, but aside from dns-warnings on the 'console' they do not show up in the output (eve-log, fast.log, alert.log). The syslog-source or alert src-ip fields check out but the host field is always the processors name.
Maybe there is a better setup?
Berend