<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk_Server is showing different server than the one in outputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447957#M77896</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We currently in  the  process  of moving  to  indexer clustering with  3 new  servers.  The  3  old servers are standalone. After setting  up  the 3 new cluster peers and verify that the command ran  for this are correct, i decided to send data to them. In my  outputs.conf, i have only specified ONE peer from the new indexer cluster. However, when data is sent and indexed,  the search head shows the splunk_server field with a value of our old server There are no references to that server name in any of the conf files either.. My machine has never sent data to the old  servers so i am not sure whats going....&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7510i6D59CAF8EF4C65E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2019 13:22:07 GMT</pubDate>
    <dc:creator>jordanking1992</dc:creator>
    <dc:date>2019-08-15T13:22:07Z</dc:date>
    <item>
      <title>Splunk_Server is showing different server than the one in outputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447957#M77896</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We currently in  the  process  of moving  to  indexer clustering with  3 new  servers.  The  3  old servers are standalone. After setting  up  the 3 new cluster peers and verify that the command ran  for this are correct, i decided to send data to them. In my  outputs.conf, i have only specified ONE peer from the new indexer cluster. However, when data is sent and indexed,  the search head shows the splunk_server field with a value of our old server There are no references to that server name in any of the conf files either.. My machine has never sent data to the old  servers so i am not sure whats going....&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7510i6D59CAF8EF4C65E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 13:22:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447957#M77896</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2019-08-15T13:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_Server is showing different server than the one in outputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447958#M77897</link>
      <description>&lt;P&gt;In what time range you're searching and is the old indexer not receiving any data in that time frame? Is your search head searching to both old and new indexers?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 13:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447958#M77897</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-08-15T13:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_Server is showing different server than the one in outputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447959#M77898</link>
      <description>&lt;P&gt;Timerange was in the last 15 minutes that i sent demo data. The searchheads are tied to the 3 old servers and the master_node that searches the three new. I am sending data to only one of new (cluster) nodes.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 14:00:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447959#M77898</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2019-08-15T14:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_Server is showing different server than the one in outputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447960#M77899</link>
      <description>&lt;P&gt;Can you login to Splunk web of that indexer and run the search? Just confirm if the data is indeed ingested on that old indexer or not.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 14:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447960#M77899</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-08-15T14:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_Server is showing different server than the one in outputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447961#M77900</link>
      <description>&lt;P&gt;Weird. Yes, it  is in fact indexed on that server and NOT the new cluster node specified in my outputs.conf. There is no reference to that server when using btool to check outputs.conf....&lt;/P&gt;

&lt;P&gt;Could this be a bug or some type of network routing issue?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 15:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447961#M77900</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2019-08-15T15:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_Server is showing different server than the one in outputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447962#M77901</link>
      <description>&lt;P&gt;root@ubuntu:/opt/splunk/etc/system/local# splunk btool outputs list --debug&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf [syslog]&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf maxEventSize = 1024&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf priority = &amp;lt;13&amp;gt;&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf type = udp&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf   [tcpout]&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf ackTimeoutOnShutdown = 30&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf autoLBFrequency = 30&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf autoLBVolume = 0&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf blockOnCloning = true&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf blockWarnThreshold = 100&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES256-SHA384:ECDH-ECDSA-AES128-SHA256&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf compressed = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf connectionTimeout = 20&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf   defaultGroup = qa_cluster&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf disabled = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf dropClonedEventsOnQueueFull = 5&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf dropEventsOnQueueFull = -1&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf ecdhCurves = prime256v1, secp384r1, secp521r1&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf forceTimebasedAutoLB = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf forwardedindex.0.whitelist = .*&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf forwardedindex.1.blacklist = _.*&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf forwardedindex.2.whitelist = (_audit|_internal|_introspection|_telemetry)&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf forwardedindex.filter.disable = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf heartbeatFrequency = 30&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf indexAndForward = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf maxConnectionsPerIndexer = 2&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf maxFailuresPerInterval = 2&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf maxQueueSize = auto&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf readTimeout = 300&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf secsInFailureInterval = 1&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf sendCookedData = true&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf sslQuietShutdown = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf sslVersions = tls1.2&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf tcpSendBufSz = 0&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf useACK = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf writeTimeout = 300&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf   [tcpout:qa_cluster]&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf   forceTimebasedAutoLB = true&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf   server = susplkidxqa001.homeoffice.anfcorp.com:9997&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:44:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447962#M77901</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2020-09-30T01:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_Server is showing different server than the one in outputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447963#M77902</link>
      <description>&lt;P&gt;Login to the &lt;CODE&gt;host&lt;/CODE&gt; that has that event and run this command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunk*/bin/splunk btool list outputs --debug
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You will see that there is a file somewhere (probably &lt;CODE&gt;/opt/splunk/etc/system/local/outputs.conf&lt;/CODE&gt;) that is pointing to the old indexer.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 21:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Server-is-showing-different-server-than-the-one-in/m-p/447963#M77902</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-08-15T21:19:10Z</dc:date>
    </item>
  </channel>
</rss>

