Hi gijoesplunk,
You should take a look this link:
https://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Inputsconf
Specifically in the section:
host = <string>
* Sets the host key/field to a static value for this stanza.
* Primarily used to control the host field, which the input applies to events
that come in through this input stanza.
* Detail: Sets the host key initial value. The input uses this key during
parsing/indexing, in particular to set the host field. It also uses this
field at search time.
* As a convenience, the input prepends the chosen string with 'host::'.
* WARNING: Do not put the <string> value in quotes. Use host=foo, not host="foo".
* If set to '$decideOnStartup', will be interpreted as hostname of executing
machine; this will occur on each splunkd startup.
* If you run multiple instances of the software on the same system (hardware
or virtual machine), choose unique values for 'host' to differentiate
your data, e.g. myhost-sh-1 or myhost-idx-2.
* The literal default conf value is $decideOnStartup, but at installation
time, the setup logic adds the local hostname as determined by DNS to the
$SPLUNK_HOME/etc/system/local/inputs.conf default stanza, which is the
effective default value.
I hope I have helped.
Rodrigo Ribeiro
... View more