Re-created with elastic-agent tag for better visibility.
Hi,
I have recently been rolling out the Endpoint agent to some host for testing.
Within the fleet agents tab, there is a single entry for each host in the format "hostname".
However within the logs-* index there are two host names for each host in the following formats, "hostname" and "hostname.domain.name.here" .
This is then showing as two separate hosts under the SIEM hosts location.
Here is a screen grab from the logs-* index , you can see i could filter by host.hostname:"IPPLAP067" but IPPLAP067.ipperf.local is also available in the index
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.