Hello Splunkers,
I'm trying to validate that engineers have successfully deployed forwarders on all required systems. All Sites have their own index. So I'm running the following search to check:
index=siteA | stats count by host
This returns the hosts, but for my Linux machines I see "machineA" followed by "machineA.siteA.local."
Does anyone have any insight as to what might be the problem? Per my instructions, the engineers have uninstalled old forwarders before installing a new version for our Splunk rebuild.
Thanks so much!
Some inputs can return the shortname and some return the FQDN. Check to ensure your forwarder's inputs.conf hostname under [default] matches the name in server.conf and that any other inputs do not specify a host explicitly.