I am seeing many invalid hosts in the windows app drop down.
such as
e-805a6aa89743
i do see these on some of our indexers gathering in large meta files
$SPLUNK_HOME/var/lib/splunk/defaultdb/db/Hosts.data
Would cleaning these metadata files clear them from the dropdown?
Where else are these coming from?
If this is from hosts.data, then you cannot really change it, the file is regenerated or extracted from each bucket.
Instead you should check the xml of the windows app page to find the search/macro used to retrieve that list and tweak it to remove the wrong host pattern. (probably a search like | metadata type=host index=os
)
If this is from hosts.data, then you cannot really change it, the file is regenerated or extracted from each bucket.
Instead you should check the xml of the windows app page to find the search/macro used to retrieve that list and tweak it to remove the wrong host pattern. (probably a search like | metadata type=host index=os
)
Yann, ok thanks i'll go this route