<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder's hostname in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51281#M9831</link>
    <description>&lt;P&gt;You can add the field if needed....&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 May 2012 18:41:58 GMT</pubDate>
    <dc:creator>briang67</dc:creator>
    <dc:date>2012-05-14T18:41:58Z</dc:date>
    <item>
      <title>Forwarder's hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51278#M9828</link>
      <description>&lt;P&gt;What is the best way to change the hostname's of the forwarders (Linux)? We have change our naming convention. I changed the entry in the server.conf (serverName = $HOSTNAME), stopped splunkd and then restarted on the forwarder. I checked the "Deployment Monitor" and the newly renamed machine did not show up. The old name was still in the list. I gave it 20 minutes, no change. The "Current Status" for the old name changed to "missing". I was able to search using the new name. Can someone help with step by step procedures?&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 14:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51278#M9828</guid>
      <dc:creator>khhenderson</dc:creator>
      <dc:date>2012-05-14T14:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder's hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51279#M9829</link>
      <description>&lt;P&gt;Did you try changing the "host = hostname" field in the inputs.conf on the forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 18:33:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51279#M9829</guid>
      <dc:creator>briang67</dc:creator>
      <dc:date>2012-05-14T18:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder's hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51280#M9830</link>
      <description>&lt;P&gt;There is not a line in my inputs.conf for "host" on the forwarder. It only list the directories to be monitored.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 18:38:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51280#M9830</guid>
      <dc:creator>khhenderson</dc:creator>
      <dc:date>2012-05-14T18:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder's hostname</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51281#M9831</link>
      <description>&lt;P&gt;You can add the field if needed....&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2012 18:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-s-hostname/m-p/51281#M9831</guid>
      <dc:creator>briang67</dc:creator>
      <dc:date>2012-05-14T18:41:58Z</dc:date>
    </item>
  </channel>
</rss>

