<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Server Change of Domain in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750049#M22664</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/28010"&gt;@PrewinThomas&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks for providing the information. I'll take note of if require performing the domain change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if there happen to be deployment clients connected, I'll need to update the outputs.conf to the new destination, right??&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jul 2025 06:34:36 GMT</pubDate>
    <dc:creator>ws</dc:creator>
    <dc:date>2025-07-18T06:34:36Z</dc:date>
    <item>
      <title>Splunk Enterprise Server Change of Domain</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/749983#M22651</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to request further assistance regarding the following.&lt;/P&gt;&lt;P&gt;If I intend to change the domain of my existing All-in-One Splunk Enterprise server, what are the key areas I should be aware of, and which configuration files need to be updated?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 08:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/749983#M22651</guid>
      <dc:creator>ws</dc:creator>
      <dc:date>2025-07-17T08:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Server Change of Domain</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/749986#M22652</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276234"&gt;@ws&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you refer to changing the domain, do you mean that this is a Windows AIO Splunk instance and you're changing the domain that the server lives in? Or is it the FQDN of the servername etc that you want to change?&lt;/P&gt;&lt;P&gt;Do you have any deployment clients connecting to your Splunk instance?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please give us a little more detail about your overall architecture so that I can drill down further.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 08:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/749986#M22652</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-17T08:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Server Change of Domain</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/749999#M22653</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276234"&gt;@ws&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will be very helpful if you can share more details on your architecture and setup.&lt;/P&gt;&lt;P&gt;Changing the &lt;STRONG&gt;Windows domain membership&lt;/STRONG&gt; affects things like&lt;/P&gt;&lt;P&gt;-Domain-based authentication (LDAP/SSO)&lt;BR /&gt;-Group policies&lt;BR /&gt;-Firewall rules etc..&lt;/P&gt;&lt;P&gt;Changing the &lt;STRONG&gt;FQDN&lt;/STRONG&gt; affects:&lt;BR /&gt;-Internal hostname resolution&lt;BR /&gt;-SSL cert identity&lt;BR /&gt;-Forwarder and peer configurations if they reference FQDN directly&lt;BR /&gt;-REST API calls, HEC endpoints, scripted inputs if there's any&lt;BR /&gt;-And yes, if deployment clients connect to this instance.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 09:52:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/749999#M22653</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-17T09:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Server Change of Domain</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750002#M22654</link>
      <description>&lt;P&gt;Based on my current understanding, the following:&lt;/P&gt;&lt;P&gt;- The domain name will be changed from splunk.test1.com to splunk.test2.com.&lt;/P&gt;&lt;P&gt;- Splunk is installed on a RHEL (Red Hat Enterprise Linux) operating system.&lt;/P&gt;&lt;P&gt;- Network devices are forwarding data directly to the Splunk All-in-One (AIO) instance.&lt;/P&gt;&lt;P&gt;- There are currently no deployment clients connected.&lt;/P&gt;&lt;P&gt;- No API calls are being utilized at this time.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 10:47:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750002#M22654</guid>
      <dc:creator>ws</dc:creator>
      <dc:date>2025-07-17T10:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Server Change of Domain</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750003#M22655</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276234"&gt;@ws&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In that case mainly you need to update these .confs what i remember,&lt;/P&gt;&lt;P&gt;-server.conf -Update serverName = splunk.test2.com&lt;BR /&gt;-inputs.conf -Update host=splunk.test2.com if it were set with old name&lt;BR /&gt;-web.conf -Update mgmtHostPort if it reference old name&lt;BR /&gt;-SSL certs -Regenerate certs with new hostname if HTTPS is used&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Also check&lt;/STRONG&gt; network devices configured with this new hostname/IP and update DNS records,Firewall rules if applcicable.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 11:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750003#M22655</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-17T11:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Server Change of Domain</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750049#M22664</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/28010"&gt;@PrewinThomas&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thanks for providing the information. I'll take note of if require performing the domain change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if there happen to be deployment clients connected, I'll need to update the outputs.conf to the new destination, right??&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 06:34:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750049#M22664</guid>
      <dc:creator>ws</dc:creator>
      <dc:date>2025-07-18T06:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Server Change of Domain</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750054#M22665</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/276234"&gt;@ws&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Absolutely. You'll need to update the outputs.conf file on all forwarders that send data to this server.&lt;BR /&gt;Additionally, if this server is functioning as a deployment server, make sure to update the deploymentclient.conf file on the relevant clients as well.&lt;/P&gt;&lt;P&gt;You can also consider using a DNS alias approach(depends on your environment) if you anticipate changing hostnames again in the future, without interrupting the forwarders splunk confs.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 06:49:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Enterprise-Server-Change-of-Domain/m-p/750054#M22665</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-07-18T06:49:34Z</dc:date>
    </item>
  </channel>
</rss>

