<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dc01 and DC01 different host accoring to splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20715#M3032</link>
    <description>&lt;P&gt;Bugs can be submitted here:&lt;BR /&gt;
&lt;A href="http://www.splunk.com/support"&gt;http://www.splunk.com/support&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In my humble opinion, i didn't see much point to using the Windows app (maybe i did not spend enough time with it). Most of the default searches provided did not work with our data so i did everything from scratch in the search app. I use the search app for almost everything.&lt;/P&gt;

&lt;P&gt;Happy Splunking!&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2011 17:45:06 GMT</pubDate>
    <dc:creator>I-Man</dc:creator>
    <dc:date>2011-06-01T17:45:06Z</dc:date>
    <item>
      <title>dc01 and DC01 different host accoring to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20711#M3028</link>
      <description>&lt;P&gt;For some reason, splunk is showing one host as two, one as DC01 (example) and dc01. Is there any way to merge them?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 10:54:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20711#M3028</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2011-06-01T10:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: dc01 and DC01 different host accoring to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20712#M3029</link>
      <description>&lt;P&gt;There are some known issues (bugs) regarding how hostnames are retrieved.  Some of this is fairly difficult to control, e.g. if Splunk receives a logfile with dc01.fqdn in it, it would probably be difficult to normalize that.  It could be a bad idea to just lop off the domain.  However, there are cases where Splunk data sources (e.g. perfmon or WMI) don't use a consistent means to gather the hostname, which is stupid and hopefully being resolved soon.  All hostnames should be lowercased and the same method should be used to retrieve the hostname when dealing with scripted inputs.  I'm not sure how fqdn vs. short name should be handled though -- I think you're left with 2 entries in that case.&lt;/P&gt;

&lt;P&gt;On the upside, searches are not case sensitive for field values, so "host=dc01" will retrieve events for dc01 and DC01".&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 12:54:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20712#M3029</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2011-06-01T12:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: dc01 and DC01 different host accoring to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20713#M3030</link>
      <description>&lt;P&gt;This has also been an issue for me. While collecting logs via WMI, sometimes a machine that has a hostname of dc01 will be pulled into Splunk as dc01, DC01, or even dc01.domain.org. As mw stated, searches are not case sensitive, so i can search for all logs from this host by using host="dc01*".&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 13:40:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20713#M3030</guid>
      <dc:creator>I-Man</dc:creator>
      <dc:date>2011-06-01T13:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: dc01 and DC01 different host accoring to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20714#M3031</link>
      <description>&lt;P&gt;Yeah i guess its not that big of a deal. Is there any place where you can send a bug repport?&lt;/P&gt;

&lt;P&gt;Its a bit more strange that the windows host dont show up in the windows app, just the search upp, you see all the WineventLog:Security etc but just in the search app.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 16:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20714#M3031</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2011-06-01T16:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: dc01 and DC01 different host accoring to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20715#M3032</link>
      <description>&lt;P&gt;Bugs can be submitted here:&lt;BR /&gt;
&lt;A href="http://www.splunk.com/support"&gt;http://www.splunk.com/support&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In my humble opinion, i didn't see much point to using the Windows app (maybe i did not spend enough time with it). Most of the default searches provided did not work with our data so i did everything from scratch in the search app. I use the search app for almost everything.&lt;/P&gt;

&lt;P&gt;Happy Splunking!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 17:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20715#M3032</guid>
      <dc:creator>I-Man</dc:creator>
      <dc:date>2011-06-01T17:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: dc01 and DC01 different host accoring to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20716#M3033</link>
      <description>&lt;P&gt;Maybe you are right &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2011 17:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20716#M3033</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2011-06-01T17:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: dc01 and DC01 different host accoring to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20717#M3034</link>
      <description>&lt;P&gt;Yeah, that one's a pain. I just use &lt;CODE&gt;eval&lt;/CODE&gt; to &lt;CODE&gt;lower()&lt;/CODE&gt; the field that's causing me trouble:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | eval host=lower(host)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As stated, search qualifiers will ignore case, but this will help with the stats grouping.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2011 15:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/dc01-and-DC01-different-host-accoring-to-splunk/m-p/20717#M3034</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2011-06-02T15:02:47Z</dc:date>
    </item>
  </channel>
</rss>

