I have files on multiple servers that I need to log that are housed in a directory where the path includes the system's hostname. The issue I'm dealing with is I only want the first portion of the hostname.
For example, if my hostname is set to db01.awesomesite.com, the path I'm attempting to monitor would be /var/log/stuff/db01/otherstuff.log
A simple solution: set up symlinks with the short names, and monitor those file paths with Splunk rather than the ones with the FQDN. You will just need to ensure the symlink is created before a host starts sending data.