How do I only have one entry instead of the hostname and fqdn?
After adding my forwarded to the Splunk environment. I see the forwarded has both hostname and fqdn
I'm assuming you see the FQDN and hostname under host
in the Selected Fields section?
Your forwarder gets the name of the host from outputs.conf
on the forwarder. So you should check if your forwarders outputs.conf
has both values listed
Where do you see that? Forwarder Management? Internal logs?
Are they from the same sourcetype? Is some data making it into Splunk from another source (like syslog, etc.). It is unlikely that the hostname and fqdn are coming in from the same UF. It is more likely that there is data from some other source than just the one UF.
please paste the result of the following while logged in your source node, where UF is running
And your /etc/hosts file <- do not post this on a public forum... i wouldnt post the above without redacting some number of characters too.