<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hostnames displayed twice in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Hostnames-displayed-twice/m-p/61595#M12277</link>
    <description>&lt;P&gt;I'd like to do the opposite. . .  Is there a way, once and for all to do away with mismatched FQDN/Short names? I'd prefer to keep the short names, but when I set the inputs.conf to have a short name, I end up with FQDN's via DNS and syslog.  Do I need to have a global lookup and reference my entire internal DNS record or is there a better way?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Aug 2012 10:57:47 GMT</pubDate>
    <dc:creator>glitchcowboy</dc:creator>
    <dc:date>2012-08-28T10:57:47Z</dc:date>
    <item>
      <title>Hostnames displayed twice</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hostnames-displayed-twice/m-p/61593#M12275</link>
      <description>&lt;P&gt;I'm running Splunk on RHEL, and using the Splunk App for Linux and Unix with the Universal Forwarder. I'm getting duplicate hosts though, ie:&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;foo&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;and &lt;/P&gt;

&lt;P&gt;&lt;EM&gt;foo.bar.com&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;How can I get rid of the duplicate? I'd prefer to keep the FQDN.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2012 21:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hostnames-displayed-twice/m-p/61593#M12275</guid>
      <dc:creator>chriscolinjacks</dc:creator>
      <dc:date>2012-01-31T21:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Hostnames displayed twice</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hostnames-displayed-twice/m-p/61594#M12276</link>
      <description>&lt;P&gt;1) Check that in you local inputs.conf the host is equal to the FQDN.&lt;BR /&gt;
2) Check that the hostname of your RHEL server is set to the FQDN you configured in inputs.conf.&lt;BR /&gt;
3) Restart splunk if you have made any changes in inputs.conf.&lt;BR /&gt;
4) Check the sourcetypes reporting foo by executing this search command: &lt;/P&gt;

&lt;P&gt;index=main |stats count by host source sourcetype&lt;/P&gt;

&lt;P&gt;The result set should show you what logs are reporting foo.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2012 13:00:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hostnames-displayed-twice/m-p/61594#M12276</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2012-02-01T13:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Hostnames displayed twice</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Hostnames-displayed-twice/m-p/61595#M12277</link>
      <description>&lt;P&gt;I'd like to do the opposite. . .  Is there a way, once and for all to do away with mismatched FQDN/Short names? I'd prefer to keep the short names, but when I set the inputs.conf to have a short name, I end up with FQDN's via DNS and syslog.  Do I need to have a global lookup and reference my entire internal DNS record or is there a better way?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Aug 2012 10:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Hostnames-displayed-twice/m-p/61595#M12277</guid>
      <dc:creator>glitchcowboy</dc:creator>
      <dc:date>2012-08-28T10:57:47Z</dc:date>
    </item>
  </channel>
</rss>

