Splunk Enterprise

Universal Forwarder shows up as both hostname and fqdn in search engine (Splunk Console)

mikev63
New Member

How do I only have one entry instead of the hostname and fqdn?

After adding my forwarded to the Splunk environment. I see the forwarded has both hostname and fqdn

Tags (1)
0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm assuming you see the FQDN and hostname under host in the Selected Fields section?

Your forwarder gets the name of the host from outputs.conf on the forwarder. So you should check if your forwarders outputs.conf has both values listed

0 Karma

xpac
SplunkTrust
SplunkTrust

Where do you see that? Forwarder Management? Internal logs?

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Are they from the same sourcetype? Is some data making it into Splunk from another source (like syslog, etc.). It is unlikely that the hostname and fqdn are coming in from the same UF. It is more likely that there is data from some other source than just the one UF.

0 Karma

kamal2222ahmed
Explorer

please paste the result of the following while logged in your source node, where UF is running

  1. hostname -A
  2. hostname -d
  3. hostname -i
  4. hostname -s

And your /etc/hosts file <- do not post this on a public forum... i wouldnt post the above without redacting some number of characters too.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...