Getting Data In

Difference between 'show default-hostname' and 'show servername'

nocostk
Communicator

When running these two commands on a host I get different values. What (if any) is the difference between the two?

# /opt/splunk/bin/splunk show default-hostname
Default hostname for data inputs: sapi09.
# /opt/splunk/bin/splunk show servername
Server name: sapi09.mydomain.com-$USER
Tags (1)

Paolo_Prigione
Builder
  • servername is used to identify the Splunk instance for features such as distributed search and defaults to <hostname>-<user running splunk>. You set this in server.conf.
  • default-hostname is used as default "host" field on all events coming from that Splunk instance. You set this in inputs.conf.
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

&#x1f5e3; You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...