<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: with inputs.conf:connection_host=dns, events are being logged where host=[ip address].  Why in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/with-inputs-conf-connection-host-dns-events-are-being-logged/m-p/133541#M27446</link>
    <description>&lt;P&gt;Similar Problem here, Version 5.0.1 on Solaris my HWF is refusing connections when the first DNS server listed in /etc/resolv.conf is not available.&lt;/P&gt;

&lt;P&gt;I had to change the order of the DNS servers and restart nscd for it to recover.&lt;/P&gt;

&lt;P&gt;It assume the reason is a timeout in DNS resolution, this should be able to be configured.&lt;/P&gt;</description>
    <pubDate>Sun, 08 Jun 2014 16:09:31 GMT</pubDate>
    <dc:creator>rabbidroid</dc:creator>
    <dc:date>2014-06-08T16:09:31Z</dc:date>
    <item>
      <title>with inputs.conf:connection_host=dns, events are being logged where host=[ip address].  Why</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/with-inputs-conf-connection-host-dns-events-are-being-logged/m-p/133540#M27445</link>
      <description>&lt;P&gt;I'm running version 6.0.2 on CentOS 6.   My DNS servers are a pair of Windows Server 2008 domain controllers.   Every month, when I patch and reboot these Windows servers - which I do sequentially, Splunk writes logs to the database where host=[ip address] instead of host=[fqdn].  This breaks my alerting because my alerts are (mostly) defined by hostnames, for examplle:&lt;BR /&gt;
     host="DC*" AND "EventCode=4740"&lt;/P&gt;

&lt;P&gt;While the logs are being written with host=[ip address], these alerts will never trigger.&lt;/P&gt;

&lt;P&gt;Do I need to change the order of my dns servers listed in /etc/resolv.conf prior to rebooting my DNS servers?  Or should I expect splunk to seamlessly send queries to the 2nd DNS to get a response?&lt;/P&gt;

&lt;P&gt;Does splunk perform it's own DNS queries or does it rely on the underlying OS?&lt;BR /&gt;
If it performs its own queries, is that configurable?  Will changing the order of entries in /etc/resolv.conf require restarting Splunk?&lt;/P&gt;

&lt;P&gt;I'd prefer to fix this wholly within Splunk, and without having to restart it monthly, because it takes 15 minutes to shut down.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 14:57:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/with-inputs-conf-connection-host-dns-events-are-being-logged/m-p/133540#M27445</guid>
      <dc:creator>tvaniderstine</dc:creator>
      <dc:date>2014-04-16T14:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: with inputs.conf:connection_host=dns, events are being logged where host=[ip address].  Why</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/with-inputs-conf-connection-host-dns-events-are-being-logged/m-p/133541#M27446</link>
      <description>&lt;P&gt;Similar Problem here, Version 5.0.1 on Solaris my HWF is refusing connections when the first DNS server listed in /etc/resolv.conf is not available.&lt;/P&gt;

&lt;P&gt;I had to change the order of the DNS servers and restart nscd for it to recover.&lt;/P&gt;

&lt;P&gt;It assume the reason is a timeout in DNS resolution, this should be able to be configured.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Jun 2014 16:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/with-inputs-conf-connection-host-dns-events-are-being-logged/m-p/133541#M27446</guid>
      <dc:creator>rabbidroid</dc:creator>
      <dc:date>2014-06-08T16:09:31Z</dc:date>
    </item>
  </channel>
</rss>

