Deployment Architecture

Why do I see the same host twice?

dmitchell92
New Member

Hello Splunkers,

When I search to see that host are in the appropriate index "index=indexname | stats count by host" I will see the same host listed twice. Once with the hostname of the forwarder and another with the FQDN of the forwarder. I believe that that culprit of this issue is because when engineers install forwards on host, they run "./splunk set forward-server ip_address:9997" then me as the splunk admin will add the sendtoindexer deployment app to the server class. Am I on the right track here or way off basis?

Thanks Splunkers!

0 Karma

pradeepkumarg
Influencer
0 Karma

dmitchell92
New Member

This helps makes better sense of the culprit. What is best practice so I can eliminate the multiple host reporting? Across our infrastructure we have a unique naming convention so I would prefer everything to not have the FQDN in the host field.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...