I see the same host in my Summary page in Search app with same event count.
They are the same host but show up like: hostname123_xxx.domain.suffix hostname123.domain.suffix
Can I make them both show as just hostname123 going forward?
Here is a similar thread that discusses how host names are assigned: http://answers.splunk.com/questions/1308/syslog-ng-logs-show-as-hostlocalserver-rather-than-remote
Here is a similar thread that discusses how host names are assigned: http://answers.splunk.com/questions/1308/syslog-ng-logs-show-as-hostlocalserver-rather-than-remote