Getting Data In

Single host is showing up as multiple sources (i.e. server1 and ip-server1). How can I clean this up?

jgilligan1985
New Member

Greetings,

In splunk search, some of the hosts are showing under multiple host names. I would like to combine the hostnames into one hostname for cleanup purposes. I fixed the initial reporting issue, but cannot seem to figure out how to make the logs show up under 1 host.

Example: server1 and ip-server1 are the same host, but show as 2 sources. I would like both sources show as server1.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Do you have rules in your props and transforms config files that are setting the host values, and thus making different host names in your data?

0 Karma

jgilligan1985
New Member

I'm working with a relatively unconfigured install. I have a rule that makes the FQDN related back to the host name. I'm not sure how to make the host names that are generated by Amazon Web Services relate to a host name that is very different.

I'm just looking to clean up the host list under Search and Reporting and merge the data from the old host names to the correct new host name so I'm not seeing 20 host names instead of the 10 that should be there.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Are the events coming from different sources (i.e. some from syslog and some from UF)?

0 Karma

jgilligan1985
New Member

(Forgive me, I'm just the clean up person on this.)

It looks like some of them are coming from /var/log/messages and the rest are combined under the other hostname from the rest of the logs (syslogd, audit, secure, etc) .

Also, some of the original logs are migrated over from a syslogd server. So there is an issue where plunk sees the old logs as the host name from them and then the FQDN from the new ones.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...