<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Will Splunk update the host field in indexed events if a universal forwarder's system name is changed? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Will-Splunk-update-the-host-field-in-indexed-events-if-a/m-p/286706#M54746</link>
    <description>&lt;P&gt;With several thousand forwarders it seems that the risk of having an incorrectly named host would be high.  Is there a better way to manage this other than reverse DNS lookup?&lt;/P&gt;

&lt;P&gt;Any idea what does the following setting in inputs.conf does?  &lt;/P&gt;

&lt;P&gt;host = &lt;BR /&gt;
* If set to '$decideOnStartup', will be interpreted as hostname of executing&lt;BR /&gt;
  machine; this will occur on each splunkd startup.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Feb 2017 23:38:21 GMT</pubDate>
    <dc:creator>john_dagostino</dc:creator>
    <dc:date>2017-02-06T23:38:21Z</dc:date>
    <item>
      <title>Will Splunk update the host field in indexed events if a universal forwarder's system name is changed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-Splunk-update-the-host-field-in-indexed-events-if-a/m-p/286704#M54744</link>
      <description>&lt;P&gt;So after months of battling an issue with our indexers dropping connections, we determined that there was a problem with the indexers performing reverse DNS lookups for the connecting servers.  To mitigate, we added 'connection_host = none' to the inputs.conf resolving the issue.&lt;/P&gt;

&lt;P&gt;If I understand how the host field in the indexed events is populated correctly, with 'connection_host = none' set on the indexers we will now rely on the 'host = ' field in inputs.conf on the UF's.   I know this value is automatically populated with the server name when Splunk is first installed, however what happens if a server is renamed?  Will it modify the inputs.conf to replace the 'host =' field with the new server name?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 19:17:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-Splunk-update-the-host-field-in-indexed-events-if-a/m-p/286704#M54744</guid>
      <dc:creator>john_dagostino</dc:creator>
      <dc:date>2017-02-06T19:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Will Splunk update the host field in indexed events if a universal forwarder's system name is changed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-Splunk-update-the-host-field-in-indexed-events-if-a/m-p/286705#M54745</link>
      <description>&lt;P&gt;It won't. You can change the default host fields name using method described here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/154999/how-can-i-change-the-default-hostname-in-splunk.html"&gt;https://answers.splunk.com/answers/154999/how-can-i-change-the-default-hostname-in-splunk.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 21:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-Splunk-update-the-host-field-in-indexed-events-if-a/m-p/286705#M54745</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-06T21:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Will Splunk update the host field in indexed events if a universal forwarder's system name is changed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-Splunk-update-the-host-field-in-indexed-events-if-a/m-p/286706#M54746</link>
      <description>&lt;P&gt;With several thousand forwarders it seems that the risk of having an incorrectly named host would be high.  Is there a better way to manage this other than reverse DNS lookup?&lt;/P&gt;

&lt;P&gt;Any idea what does the following setting in inputs.conf does?  &lt;/P&gt;

&lt;P&gt;host = &lt;BR /&gt;
* If set to '$decideOnStartup', will be interpreted as hostname of executing&lt;BR /&gt;
  machine; this will occur on each splunkd startup.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2017 23:38:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-Splunk-update-the-host-field-in-indexed-events-if-a/m-p/286706#M54746</guid>
      <dc:creator>john_dagostino</dc:creator>
      <dc:date>2017-02-06T23:38:21Z</dc:date>
    </item>
  </channel>
</rss>

