We have configured a number of our Cherwell servers to send data to Splunk on our Management port 89 ( default 8089 ). Issue is we have a few servers with the same name in different domains, so we need the host to be the FQDN, host.domain.com. Where or how would I set this? Is this a global setting? is that port considered an input and I can set a connect_host for it?
{ [-]
Level: WARN
Message: Duplicate script key being added with key: [postInitMenu]; value: []; type: [Startup]
ThreadName: Thread_22
TimeStamp: 2016-08-17T15:29:23.9734481-04:00
pid: 4288
Show as raw text
host = **CWAPP01** source = w3wp sourcetype = Cherwell