|
After initial installation of the forwarder when the Splunk service is started the forwarder reports by Ip Address.After we configure the hostn name to FQDN it starts reporting by FQDN.However in the metadata shows there are two hosts one by IP and the other by FQDN. How do I delete the IP from the metadata or the Summary Index. |
|
Removing anything from your metadata rather complicated. To do it correctly you have to re-index your data. Which, like it sounds, is a lot of work. If your real issue issue with summary indexing, you can always just delete the old events. Then you can modify your saved searches to add a Another variation would be to use the Also, make sure you read up on the Another really simple way to deal with this is to simply tag your |
