<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Index changes after Device IP changed and hardware refreshed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-changes-after-Device-IP-changed-and-hardware-refreshed/m-p/661290#M111782</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the log source (e.g. index=my_index) at my company's splunk became inter=main. After multiple investigation, i found that Infrastructure Team has refreshed the device to a new hardware due to product EOL (same brand, same product, e.g. Palo Alto 3020 to PA3220). Also, the device IP is changed.&lt;/P&gt;&lt;P&gt;Thus, i have modified the monitoring path at inputs.conf in Add-on and distribute to HF by deployment server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the example for what i modified:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///siem/data/syslog/192.168.1.101/*] #original ip was 192.168.1.100&amp;nbsp;&lt;/P&gt;&lt;P&gt;disabled = false&amp;nbsp;&lt;/P&gt;&lt;P&gt;index = my_index&lt;/P&gt;&lt;P&gt;sourcetype = my:sourcetype&lt;/P&gt;&lt;P&gt;host_segment = 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After such changes, i tried to verify the result on HF, the inputs.conf was successfully update to the new version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the logs remain to index=main when searching on Search Head after the changes i did above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone know if any other thing i need to modify? Or else there are other root cause that making the logs fall under wrong index apart from the ip changes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2023 04:27:58 GMT</pubDate>
    <dc:creator>splunk_newbie3</dc:creator>
    <dc:date>2023-10-19T04:27:58Z</dc:date>
    <item>
      <title>Index changes after Device IP changed and hardware refreshed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-changes-after-Device-IP-changed-and-hardware-refreshed/m-p/661290#M111782</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the log source (e.g. index=my_index) at my company's splunk became inter=main. After multiple investigation, i found that Infrastructure Team has refreshed the device to a new hardware due to product EOL (same brand, same product, e.g. Palo Alto 3020 to PA3220). Also, the device IP is changed.&lt;/P&gt;&lt;P&gt;Thus, i have modified the monitoring path at inputs.conf in Add-on and distribute to HF by deployment server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the example for what i modified:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///siem/data/syslog/192.168.1.101/*] #original ip was 192.168.1.100&amp;nbsp;&lt;/P&gt;&lt;P&gt;disabled = false&amp;nbsp;&lt;/P&gt;&lt;P&gt;index = my_index&lt;/P&gt;&lt;P&gt;sourcetype = my:sourcetype&lt;/P&gt;&lt;P&gt;host_segment = 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After such changes, i tried to verify the result on HF, the inputs.conf was successfully update to the new version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the logs remain to index=main when searching on Search Head after the changes i did above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone know if any other thing i need to modify? Or else there are other root cause that making the logs fall under wrong index apart from the ip changes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 04:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-changes-after-Device-IP-changed-and-hardware-refreshed/m-p/661290#M111782</guid>
      <dc:creator>splunk_newbie3</dc:creator>
      <dc:date>2023-10-19T04:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Index changes after Device IP changed and hardware refreshed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-changes-after-Device-IP-changed-and-hardware-refreshed/m-p/661296#M111783</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;your changes apply only to new events not to those which are already indexed.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 06:16:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-changes-after-Device-IP-changed-and-hardware-refreshed/m-p/661296#M111783</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-10-19T06:16:40Z</dc:date>
    </item>
  </channel>
</rss>

