<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236677#M46021</link>
    <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;Duplicate instance name. Ensure each instance has a unique instance (host) name.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;This message highlights &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/DMC/DMCprerequisites"&gt;one of the DMC requirements&lt;/A&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Make sure that each instance in the deployment (each search head, license master, and so on) has a unique server.conf serverName value and inputs.conf host value.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I would hope that the "Learn More" link should take you to a documentation topic that points out this requirement. If not, please let me know and I'll file a bug.&lt;/P&gt;

&lt;P&gt;In essence, all instances monitored by the DMC need to have different values for both of the following properties that set the instance's name:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;server.conf / &lt;CODE&gt;[general]&lt;/CODE&gt; / &lt;CODE&gt;serverName&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;inputs.conf / &lt;CODE&gt;[default]&lt;/CODE&gt; / &lt;CODE&gt;host&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In your case, you need to edit &lt;CODE&gt;etc/system/local/inputs.conf&lt;/CODE&gt; on instance "marigold-ds" and set the value of &lt;CODE&gt;host&lt;/CODE&gt; in the &lt;CODE&gt;[default]&lt;/CODE&gt; stanza to "marigold-ds", then restart this instance and run the DMC setup again.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2016 21:01:00 GMT</pubDate>
    <dc:creator>hexx</dc:creator>
    <dc:date>2016-08-24T21:01:00Z</dc:date>
    <item>
      <title>Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236672#M46016</link>
      <description>&lt;P&gt;Hi.   &lt;/P&gt;

&lt;P&gt;I'm wondering if I'm missing something here, but it seems like I can't manage a server that has more than one Splunk instance on it using the Distributed Management Console (Splunk 6.4+).&lt;/P&gt;

&lt;P&gt;I noticed that I needed to have a different serverName set via server.conf in order to be able to add it as a search peer on my DMC. So same hostname, but different instance name and, of course, different management port.   When I go to the DMC Setup page to turn on monitoring on my second instance and then hit Apply, I get&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;You have some unresolved errors that need to be fixed before you can proceed. Check the problems column and expand for more detail.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and then under the specific hosts (both entries with the same hostname but different instance names show this):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Duplicate instance name. Ensure each instance has a unique instance (host) name.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I don't see a way around this and it's kind of a bummer to not be able to see some of my deployment servers' status in the DMC.  It's frustrating that I've done what was needed to make Splunk accept the second instance as a search peer, but the DMC wants more than that.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 22:41:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236672#M46016</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2016-08-23T22:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236673#M46017</link>
      <description>&lt;P&gt;Did you try changing the instance name for one of the instances on that server?&lt;/P&gt;

&lt;P&gt;server.conf&lt;BR /&gt;
&lt;PRE&gt;&lt;BR /&gt;
[general]&lt;BR /&gt;
serverName =  yourHost_someidentifier_to_identify_the_instance&lt;BR /&gt;
-The name used to identify this Splunk instance for features such as&lt;BR /&gt;
  distributed search.&lt;BR /&gt;
-Defaults to hostname&lt;BR /&gt;
&lt;/PRE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236673#M46017</guid>
      <dc:creator>pradeepkumarg</dc:creator>
      <dc:date>2020-09-29T10:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236674#M46018</link>
      <description>&lt;P&gt;Yeah, as I mentioned I had to set a different instance name via server.conf in order to even add that second instance as a search peer.   But despite the fact that that makes the search peer configuration happy, it's apparently not enough to make the DMC happy enough to add it.   Or at least to let the DMC start monitoring it because the machine name is the same.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 13:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236674#M46018</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2016-08-24T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236675#M46019</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;But despite the fact that that makes the search peer configuration happy, it's apparently not enough to make the DMC happy enough to add it. Or at least to let the DMC start monitoring it because the machine name is the same.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;@mfrost8, this is unexpected. While the DMC &lt;EM&gt;requires&lt;/EM&gt; for the instances it monitors to be uniquely identifiable based on the values of "host" (as defined in inputs.conf / host) and "splunk_server" (as defined in server.conf / serverName) associated with the events they read &amp;amp; return, "machine" (which represents the hostname of the &lt;EM&gt;server&lt;/EM&gt; on which the Splunk instance is running) does not need to be unique.&lt;/P&gt;

&lt;P&gt;While co-hosting Splunk instances is not something we necessarily recommend, it &lt;EM&gt;is&lt;/EM&gt; supported to monitor co-hosted instances with the DMC.&lt;/P&gt;

&lt;P&gt;Can you be more specific about the behavior you are seeing?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 16:41:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236675#M46019</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2016-08-24T16:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236676#M46020</link>
      <description>&lt;P&gt;It was unexpected to me too :-).f&lt;/P&gt;

&lt;P&gt;I have 3 servers this way -- with 2 instances, one using the normal 8089 mgmt port and one using 8189.   All are Linux servers.  Let's consider the server I'll call "marigold".   Note that "marigold" is a more user-friendly DNS CNAME for the host that we use within Splunk rather than the regular hostname which is less pleasant -- we'll call that "mg1234.example.com".  The $SPLUNK_HOME/etc/system/local/server.conf file has&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...
[general]
serverName = marigold
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The secondary instance on that same server (the one using port 8189 as a management port) has&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...
[general]
serverName = marigold-ds
...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My first step in getting the DMC to recognize these instances was to add them as search peers on the DMC.  I had no problem adding the "marigold" instance, but then discovered that it wouldn't take the second instance unless I set the serverName differently in server.conf above.   After I did that, they both had an OK status in the search peers listing on the DMC.&lt;/P&gt;

&lt;P&gt;If I then go to Settings-&amp;gt;General Setup on the DMC I see both instances listed.   At this point, I'd already successfully configured the "marigold" instance so it shows as configured.  So I see&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Instance (host)     Instance (serverName)    Machine   ...   Monitoring    State
mg1234                 marigold                        mg1234          Enabled         Configured
mg1234                 marigold-ds                  mg1234           Enabled         New
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;(on a side note, why is the Instance(host) column a large font size than the rest of the table?)&lt;/P&gt;

&lt;P&gt;If I expand these I have the following for the first entry (remembering that marigold.example.com is a DNS CNAME for mg1234.example.com)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Peer URI    marigold.example.com:8089
OS              Linux
Cores         1
RAM           3964MB
Version      6.4.3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Peer URI    marigold.example.com:8189
OS              Linux
Cores         1
RAM           3964MB
Version      6.4.3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If I select the second entry (marigold-ds -- the one that's marked as "new") and hit the drop-down to the right to Edit Server Roles then change it to a deployment server, I get the pop-up that tells me this was done successfully.   I then scroll up and click on Apply Changes.   Now I get the Error pop-up with&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;You have some unresolved errors that need to be fixed before you can proceed. Check the problems column and expand for more detail.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The little red triangle exclamation marks are to the right of the marigold and marigold-ds entries.    When I expand either of the two rows they both now show:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Duplicate instance name. Ensure each instance has a unique instance (host) name.
Resolve these problems to ensure that your dashboards are complete. Learn more
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and that's about it.   Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 18:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236676#M46020</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2016-08-24T18:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236677#M46021</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;Duplicate instance name. Ensure each instance has a unique instance (host) name.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;This message highlights &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/DMC/DMCprerequisites"&gt;one of the DMC requirements&lt;/A&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Make sure that each instance in the deployment (each search head, license master, and so on) has a unique server.conf serverName value and inputs.conf host value.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I would hope that the "Learn More" link should take you to a documentation topic that points out this requirement. If not, please let me know and I'll file a bug.&lt;/P&gt;

&lt;P&gt;In essence, all instances monitored by the DMC need to have different values for both of the following properties that set the instance's name:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;server.conf / &lt;CODE&gt;[general]&lt;/CODE&gt; / &lt;CODE&gt;serverName&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;inputs.conf / &lt;CODE&gt;[default]&lt;/CODE&gt; / &lt;CODE&gt;host&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In your case, you need to edit &lt;CODE&gt;etc/system/local/inputs.conf&lt;/CODE&gt; on instance "marigold-ds" and set the value of &lt;CODE&gt;host&lt;/CODE&gt; in the &lt;CODE&gt;[default]&lt;/CODE&gt; stanza to "marigold-ds", then restart this instance and run the DMC setup again.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 21:01:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236677#M46021</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2016-08-24T21:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236678#M46022</link>
      <description>&lt;P&gt;Aha.   Thanks.   So then does it matter if the hostname listed in the second instance (marigold-ds in this example) is not a real hostname or alias?   That is, Splunk will work with it just fine if it's just an arbitrary label that isn't resolvable to anything in DNS?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 21:17:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236678#M46022</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2016-08-24T21:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236679#M46023</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;does it matter if the hostname listed in the second instance (marigold-ds in this example) is not a real hostname or alias?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;No, it doesn't matter. The settings we are talking about here represent an arbitrary label for your Splunk instance, which can be completely decorrelated with the hostname of the &lt;EM&gt;server&lt;/EM&gt; that the instance runs on.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 01:09:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236679#M46023</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2016-08-25T01:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236680#M46024</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;(on a side note, why is the Instance(host) column a large font size than the rest of the table?)&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;I think the idea there is to highlight / underscore the "primary" instance name that the DMC uses to identify instances. It should probably be "Instance (serverName)" that is highlighted, though, as it is that value that we use to populate the "instance" pull-downs. I'll file a bug.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 01:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236680#M46024</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2016-08-25T01:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to add hosts with more than one Splunk instance to the Distributed Management Console?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236681#M46025</link>
      <description>&lt;P&gt;Great.   This seems to have done it for me.  I guess I missed this point about the hostnames in the documentation.   It was made a little bit more confusing in that the definition/addition of search peers on the DMC then isn't as picky and can use the same DNS hostname with a different port.&lt;/P&gt;

&lt;P&gt;In any case, I'm all set now.   Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 16:05:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-add-hosts-with-more-than-one-Splunk-instance/m-p/236681#M46025</guid>
      <dc:creator>mfrost8</dc:creator>
      <dc:date>2016-08-25T16:05:25Z</dc:date>
    </item>
  </channel>
</rss>

