Getting Data In

Single host is showing up as multiple sources (i.e. server1 and ip-server1). How can I clean this up?

jgilligan1985
New Member

Greetings,

In splunk search, some of the hosts are showing under multiple host names. I would like to combine the hostnames into one hostname for cleanup purposes. I fixed the initial reporting issue, but cannot seem to figure out how to make the logs show up under 1 host.

Example: server1 and ip-server1 are the same host, but show as 2 sources. I would like both sources show as server1.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Do you have rules in your props and transforms config files that are setting the host values, and thus making different host names in your data?

0 Karma

jgilligan1985
New Member

I'm working with a relatively unconfigured install. I have a rule that makes the FQDN related back to the host name. I'm not sure how to make the host names that are generated by Amazon Web Services relate to a host name that is very different.

I'm just looking to clean up the host list under Search and Reporting and merge the data from the old host names to the correct new host name so I'm not seeing 20 host names instead of the 10 that should be there.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Are the events coming from different sources (i.e. some from syslog and some from UF)?

0 Karma

jgilligan1985
New Member

(Forgive me, I'm just the clean up person on this.)

It looks like some of them are coming from /var/log/messages and the rest are combined under the other hostname from the rest of the logs (syslogd, audit, secure, etc) .

Also, some of the original logs are migrated over from a syslogd server. So there is an issue where plunk sees the old logs as the host name from them and then the FQDN from the new ones.

0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...