All Apps and Add-ons

windows app hosts dropdown very large are these indexer from hosts.data ?

sonicZ
Contributor

alt textI am seeing many invalid hosts in the windows app drop down.
such as
e-805a6aa89743

i do see these on some of our indexers gathering in large meta files

$SPLUNK_HOME/var/lib/splunk/defaultdb/db/Hosts.data

Would cleaning these metadata files clear them from the dropdown?
Where else are these coming from?

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

If this is from hosts.data, then you cannot really change it, the file is regenerated or extracted from each bucket.

Instead you should check the xml of the windows app page to find the search/macro used to retrieve that list and tweak it to remove the wrong host pattern. (probably a search like | metadata type=host index=os )

View solution in original post

yannK
Splunk Employee
Splunk Employee

If this is from hosts.data, then you cannot really change it, the file is regenerated or extracted from each bucket.

Instead you should check the xml of the windows app page to find the search/macro used to retrieve that list and tweak it to remove the wrong host pattern. (probably a search like | metadata type=host index=os )

sonicZ
Contributor

Yann, ok thanks i'll go this route

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...