<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Universal forwarder shows 2 host names for the same server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436777#M76202</link>
    <description>&lt;P&gt;Hi Pradeep,  Thanks. Earlier I was looking at a different inputs.conf ( in a different folder) and so the confusion.  After correcting the "correct" inputs.conf , i am all set.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jul 2018 16:03:04 GMT</pubDate>
    <dc:creator>neerajshah81</dc:creator>
    <dc:date>2018-07-17T16:03:04Z</dc:date>
    <item>
      <title>Windows Universal forwarder shows 2 host names for the same server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436771#M76196</link>
      <description>&lt;P&gt;Hello,  We have a single instance splunk deployment.   I have installed Universal Forwarder on an Win 2012 R2 Active Directory DC.  Upon checking / searching for the events in Splunk Search UI, i noticed it shows 2 different host names for the same DC server. Screenshot below.   How to resolve this ?  If i click on the 1st host "LAN-AD', it shows events related to CPU, Memory monitoring whereas if i click on the other one, this shows events related to Security Events, Application Event log etc.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5365i696876156BC748DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 19:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436771#M76196</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2018-07-12T19:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal forwarder shows 2 host names for the same server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436772#M76197</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/642834/why-are-there-multiple-host-entries-for-every-splu.html#answer-642944"&gt;https://answers.splunk.com/answers/642834/why-are-there-multiple-host-entries-for-every-splu.html#answer-642944&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 19:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436772#M76197</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2018-07-12T19:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal forwarder shows 2 host names for the same server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436773#M76198</link>
      <description>&lt;P&gt;Hi, i followed that link but don't see the solution mentioned.  I have checked my server.conf and inputs.conf file on my Universal Forwarder. Both do not have any [servername] attribute defined.  Where is the UF getting the 2 server names from ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 14:35:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436773#M76198</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2018-07-13T14:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal forwarder shows 2 host names for the same server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436774#M76199</link>
      <description>&lt;P&gt;Interesting - what does &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/inputs.conf&lt;/CODE&gt; say on the forwarder? It should have the following - &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = &amp;lt;host_name&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 13 Jul 2018 16:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436774#M76199</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-07-13T16:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal forwarder shows 2 host names for the same server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436775#M76200</link>
      <description>&lt;P&gt;Check the other answer.. I've copy pasted below.&lt;/P&gt;

&lt;P&gt;I've seen this usually with syslog (/var/log/syslog)&lt;/P&gt;

&lt;P&gt;Syslog is a pre trained sourcetype and extracts the host from within the log itself and if the log has the hostname without FQDN, you see that.&lt;/P&gt;

&lt;P&gt;Check the sourcetypes for each of those host entry |tstats count WHERE host=test* by host,sourcetype | stats values(sourcetype) by host&lt;/P&gt;

&lt;P&gt;You will see your problematic sourcetype that is causing the host value without FQDN.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jul 2018 17:09:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436775#M76200</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2018-07-16T17:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal forwarder shows 2 host names for the same server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436776#M76201</link>
      <description>&lt;P&gt;Thank you Ddrillic.  Earlier  I was looking at a different inputs.conf ( in a different folder).&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 16:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436776#M76201</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2018-07-17T16:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal forwarder shows 2 host names for the same server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436777#M76202</link>
      <description>&lt;P&gt;Hi Pradeep,  Thanks. Earlier I was looking at a different inputs.conf ( in a different folder) and so the confusion.  After correcting the "correct" inputs.conf , i am all set.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 16:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-Universal-forwarder-shows-2-host-names-for-the-same/m-p/436777#M76202</guid>
      <dc:creator>neerajshah81</dc:creator>
      <dc:date>2018-07-17T16:03:04Z</dc:date>
    </item>
  </channel>
</rss>

