Splunk Enterprise

Universal Forwarder shows up as both hostname and fqdn in search engine (Splunk Console)

mikev63
New Member

How do I only have one entry instead of the hostname and fqdn?

After adding my forwarded to the Splunk environment. I see the forwarded has both hostname and fqdn

Tags (1)
0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm assuming you see the FQDN and hostname under host in the Selected Fields section?

Your forwarder gets the name of the host from outputs.conf on the forwarder. So you should check if your forwarders outputs.conf has both values listed

0 Karma

xpac
SplunkTrust
SplunkTrust

Where do you see that? Forwarder Management? Internal logs?

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Are they from the same sourcetype? Is some data making it into Splunk from another source (like syslog, etc.). It is unlikely that the hostname and fqdn are coming in from the same UF. It is more likely that there is data from some other source than just the one UF.

0 Karma

kamal2222ahmed
Explorer

please paste the result of the following while logged in your source node, where UF is running

  1. hostname -A
  2. hostname -d
  3. hostname -i
  4. hostname -s

And your /etc/hosts file <- do not post this on a public forum... i wouldnt post the above without redacting some number of characters too.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...