<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How does Splunk resolve forwarders' hostnames when using acceptFrom? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-resolve-forwarders-hostnames-when-using/m-p/318253#M59472</link>
    <description>&lt;P&gt;I'm trying to use the "acceptFrom" property in inputs.conf to create a whitelist of hosts that can forward to my indexer. One of my hosts matches the hostname glob in my whitelist, but is denied because its hostname isn't properly resolved by Splunk:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;TcpInputProc - Rejected a connection from xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx) due to acceptFrom setting&lt;/CODE&gt; - normally the parentheses would contain a resolved hostname.&lt;/P&gt;

&lt;P&gt;Running &lt;CODE&gt;nslookup xxx.xxx.xxx.xxx&lt;/CODE&gt; from the receiving server gives the proper hostname, as well as a glob matching all subdomains of the hostname, however they are listed as non-authoritative. Does Splunk ignore non-authoritative records? Are the multiple results confusing it? How do I debug this?&lt;/P&gt;</description>
    <pubDate>Wed, 17 Jan 2018 18:26:03 GMT</pubDate>
    <dc:creator>sjodle</dc:creator>
    <dc:date>2018-01-17T18:26:03Z</dc:date>
    <item>
      <title>How does Splunk resolve forwarders' hostnames when using acceptFrom?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-resolve-forwarders-hostnames-when-using/m-p/318253#M59472</link>
      <description>&lt;P&gt;I'm trying to use the "acceptFrom" property in inputs.conf to create a whitelist of hosts that can forward to my indexer. One of my hosts matches the hostname glob in my whitelist, but is denied because its hostname isn't properly resolved by Splunk:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;TcpInputProc - Rejected a connection from xxx.xxx.xxx.xxx (xxx.xxx.xxx.xxx) due to acceptFrom setting&lt;/CODE&gt; - normally the parentheses would contain a resolved hostname.&lt;/P&gt;

&lt;P&gt;Running &lt;CODE&gt;nslookup xxx.xxx.xxx.xxx&lt;/CODE&gt; from the receiving server gives the proper hostname, as well as a glob matching all subdomains of the hostname, however they are listed as non-authoritative. Does Splunk ignore non-authoritative records? Are the multiple results confusing it? How do I debug this?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-resolve-forwarders-hostnames-when-using/m-p/318253#M59472</guid>
      <dc:creator>sjodle</dc:creator>
      <dc:date>2018-01-17T18:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk resolve forwarders' hostnames when using acceptFrom?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-resolve-forwarders-hostnames-when-using/m-p/318254#M59473</link>
      <description>&lt;P&gt;If this is from a Splunk forwarder, i believe it uses the forwarder name (rather than DNS) as recorded in etc/system/local/inputs.conf on the forwarder (or the "client name" if set)&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-resolve-forwarders-hostnames-when-using/m-p/318254#M59473</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-17T18:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: How does Splunk resolve forwarders' hostnames when using acceptFrom?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-resolve-forwarders-hostnames-when-using/m-p/318255#M59474</link>
      <description>&lt;P&gt;I don't think that's the case. While setting up my receiving server, I nmap'd it from my local machine, which does not have Splunk running. This produced &lt;CODE&gt;Rejected a connection from...&lt;/CODE&gt; logs from my workstation's IP, with a resolved hostname. This leads me to believe that the acceptFrom whitelist is checked before any Splunk-to-Splunk communication occurs.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2018 18:48:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-does-Splunk-resolve-forwarders-hostnames-when-using/m-p/318255#M59474</guid>
      <dc:creator>sjodle</dc:creator>
      <dc:date>2018-01-17T18:48:26Z</dc:date>
    </item>
  </channel>
</rss>

