<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After installing a Splunk 6.4 universal forwarder, why are events indexed with the shortname instead of FQDN for the hostname? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216024#M42509</link>
    <description>&lt;P&gt;My server.conf does have the serverName key set to my FQDN and according to splunkd.log it is honoring this setting.  The default-hostname remains the problematic piece.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2016 12:26:55 GMT</pubDate>
    <dc:creator>lib_systems</dc:creator>
    <dc:date>2016-04-21T12:26:55Z</dc:date>
    <item>
      <title>After installing a Splunk 6.4 universal forwarder, why are events indexed with the shortname instead of FQDN for the hostname?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216020#M42505</link>
      <description>&lt;P&gt;After an initial installation of the Universal Forwarder (6.4.0), I immediately changed the hostname values to use the FQDN:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk set servername myserver.domain.com
./splunk set default-hostname myserver.domain.com
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I then restart the Universal Forwarder service and confirm the changes in the following conf files:&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/system/local/inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = myserver.domain.com
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;/opt/splunkforwarder/etc/system/local/server.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[general]
serverName = myserver.domain.com
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, unless I explicitly specify the FQDN hostname, when I add a new monitor (sourcetypes linux_secure and linux_messages_syslog), the events are indexed with the shortname.&lt;/P&gt;

&lt;P&gt;The splunkd.log seems to suggest it is not honoring the default hostname I set for the inputs.conf (oddly, the servername in server.conf seems to stick):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...
04-18-2016 15:10:37.451 -0400 INFO  ServerConfig - My server name is "myserver.domain.com".
04-18-2016 15:10:37.452 -0400 INFO  ServerConfig - Found no site defined in server.conf
04-18-2016 15:10:37.452 -0400 INFO  ServerConfig - My hostname is "myserver".
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This behavior is reproducible on multiple hosts.  Is there something else I'm missing?  Any advice is appreciated.  Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:30:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216020#M42505</guid>
      <dc:creator>lib_systems</dc:creator>
      <dc:date>2020-09-29T09:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: After installing a Splunk 6.4 universal forwarder, why are events indexed with the shortname instead of FQDN for the hostname?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216021#M42506</link>
      <description>&lt;P&gt;What do you get when you run a btool list on inputs? This command from you $SPLUNK_HOME/bin directory&lt;BR /&gt;
./splunk cmd btool inputs list --debug | grep host&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 19:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216021#M42506</guid>
      <dc:creator>aladda_splunk</dc:creator>
      <dc:date>2016-04-20T19:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: After installing a Splunk 6.4 universal forwarder, why are events indexed with the shortname instead of FQDN for the hostname?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216022#M42507</link>
      <description>&lt;P&gt;All results from this command are using the desired FQDN:&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/inputs.conf                        connection_host = ip&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/inputs.conf                        connection_host = dns&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/inputs.conf                        connection_host = ip&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/inputs.conf                          host = myserver.domain.com&lt;/P&gt;

&lt;P&gt;I am seeing other posts describing the same problem [1] [2].  Both allude to the fact that regardless of the settings I configure, the host field is being overridden by the default transformers for the linux_messages_syslog sourcetype.  I've tried the suggestions of creating my own custom props.conf in the /local directory to override the default transformers, however, that has not worked for me (I did this on the universal forwarder though it's still not clear to me if that should be done there or on the indexer).&lt;/P&gt;

&lt;P&gt;Those suggestions aside, what still puzzles me is that the splunkd.log indicates the universal forwarder is not honoring my settings immediately upon startup and uses the incorrect hostname.  It feels like fiddling with custom props.conf isn't going to help in this case.&lt;/P&gt;

&lt;P&gt;[1] &lt;A href="https://answers.splunk.com/answers/149755/universal-forwarder-6-1-2-hostname-not-equal-to-servername-inputs-conf.html" target="_blank"&gt;https://answers.splunk.com/answers/149755/universal-forwarder-6-1-2-hostname-not-equal-to-servername-inputs-conf.html&lt;/A&gt;&lt;BR /&gt;
[2] &lt;A href="https://answers.splunk.com/answers/6895/can-i-prevent-the-default-index-time-extraction-for-the-host-field-to-occur-for-events-of-the-syslog-sourcetype.html" target="_blank"&gt;https://answers.splunk.com/answers/6895/can-i-prevent-the-default-index-time-extraction-for-the-host-field-to-occur-for-events-of-the-syslog-sourcetype.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:27:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216022#M42507</guid>
      <dc:creator>lib_systems</dc:creator>
      <dc:date>2020-09-29T09:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: After installing a Splunk 6.4 universal forwarder, why are events indexed with the shortname instead of FQDN for the hostname?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216023#M42508</link>
      <description>&lt;P&gt;I've noticed that 6.4 is much more strict about the serverName key in server.conf. I believe this is the new end-all be-all forwarder name. This became obvious to me in some automation testing using puppet to apply a forwarder upgrade from 6.3.3.&lt;/P&gt;

&lt;P&gt;Funny thing is this doesn't appear to be documented in &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/Aboutupgradingto6.4READTHISFIRST"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.0/Installation/Aboutupgradingto6.4READTHISFIRST&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 04:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216023#M42508</guid>
      <dc:creator>dolivasoh</dc:creator>
      <dc:date>2016-04-21T04:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: After installing a Splunk 6.4 universal forwarder, why are events indexed with the shortname instead of FQDN for the hostname?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216024#M42509</link>
      <description>&lt;P&gt;My server.conf does have the serverName key set to my FQDN and according to splunkd.log it is honoring this setting.  The default-hostname remains the problematic piece.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 12:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216024#M42509</guid>
      <dc:creator>lib_systems</dc:creator>
      <dc:date>2016-04-21T12:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: After installing a Splunk 6.4 universal forwarder, why are events indexed with the shortname instead of FQDN for the hostname?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216025#M42510</link>
      <description>&lt;P&gt;The problem is the default parsing of the host field on the &lt;STRONG&gt;indexer&lt;/STRONG&gt; for pretrained sourcetype linux_messages_syslog.&lt;BR /&gt;
You can override it with a local props.conf on the receiving indexer.&lt;/P&gt;

&lt;P&gt;Have a look at my other answer here:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/494084/linux-message-syslog-host-name-issue.html" target="_blank"&gt;https://answers.splunk.com/answers/494084/linux-message-syslog-host-name-issue.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:34:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-a-Splunk-6-4-universal-forwarder-why-are-events/m-p/216025#M42510</guid>
      <dc:creator>Raschko</dc:creator>
      <dc:date>2020-09-29T12:34:04Z</dc:date>
    </item>
  </channel>
</rss>

