Splunk Enterprise Security

Event from add-on Splunk app Windows source without domain name

ibabansk
Loves-to-Learn

Good afternoon! Splunk Add-on for Microsoft Windows version 8.0.0 Splunk TA Windows, generates a data source without a domain name, i.e. just a host name. How can I bulk configure to display hostname with domain e.g. pc1.domain.com. Use in server.conf - hostnameOption = fullyqualifiedname, you can not because you need to distribute the configuration on a large number of PC
via forwarder manager. Such a setup can be done through props and transformer

Labels (1)
0 Karma

ibabansk
Loves-to-Learn

Thank you for the solution provided, but unfortunately it is not applicable. The thing is that in fact we get two event sources Computer1 and Computer1.local.domain. If you disable Splunk Add-on for Microsoft, all events come from the source Computer1.local.domain

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

This isn't exactly the answer to the question that you've asked, but if you're using Enterprise Security, it sounds like you could possibly use entity zones to help specify your different domains: 
https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Entityzones

Let me know if that helps. 

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...