<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk configured with new VMs in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13768#M10130</link>
    <description>&lt;P&gt;This solution worked.  We've configure this into the template and created several new machines with no problems.  &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2010 19:54:07 GMT</pubDate>
    <dc:creator>trent6</dc:creator>
    <dc:date>2010-05-20T19:54:07Z</dc:date>
    <item>
      <title>Splunk configured with new VMs</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13765#M10127</link>
      <description>&lt;P&gt;I am attempting to setup Splunk on a VM that will become a VM template.  I have run sysprep and made it a template.  I create a new VM from the template, and it receives new machine name and IP address.
The problem is that when it reports to Splunk, it has shows up under the old Hostname entry.  I see current entries that state :
Host: oldName , Computername: oldName 
and other entries that state 
Host: oldName, Computername: newName&lt;/P&gt;

&lt;P&gt;We are forwarding Windows event logs to a master Listener.
I see at least 3 places where the machine name is configured.  Inputs.conf and 2 different server.conf files.
What is the best way for us to automate this?&lt;/P&gt;

&lt;P&gt;Thanks,
Trent&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2010 22:53:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13765#M10127</guid>
      <dc:creator>trent6</dc:creator>
      <dc:date>2010-05-18T22:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk configured with new VMs</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13766#M10128</link>
      <description>&lt;P&gt;I had an SA clone solaris boxes that had Splunk forwarder installed and noticed the same thing.  There was another question about this and I followed their ideas and removed the host=(servername) from the servers.conf and my servers were able to pick up the correct name.  &lt;/P&gt;

&lt;P&gt;Here is the link to the other topic:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/questions/794/how-to-change-hostname-of-a-splunk-server/807#807" rel="nofollow"&gt;http://answers.splunk.com/questions/794/how-to-change-hostname-of-a-splunk-server/807#807&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So you could delete the setting and then make your template.  &lt;/P&gt;

&lt;P&gt;Travis.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2010 23:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13766#M10128</guid>
      <dc:creator>thall79</dc:creator>
      <dc:date>2010-05-18T23:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk configured with new VMs</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13767#M10129</link>
      <description>&lt;P&gt;The &lt;EM&gt;right&lt;/EM&gt; way to do this would be to remove the generated files that have the host name (there are only two: server.conf and inputs.conf) and force Splunk to regenerate this with the first-time run process. Unfortunately I don't know how to force this. So instead:&lt;/P&gt;

&lt;P&gt;With server.conf, you can actually simply replace it with one that uses the $HOSTNAME environment variable:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;serverName = $HOSTNAME
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;instead of a literal hostname. However, as of the current version (4.1.2) this doesn't work in inputs.conf, leaving you with the option of just generating a new one of those files yourself. It's not very hard, but it is an unnecessary pain in the ass.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 19:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13767#M10129</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-19T19:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk configured with new VMs</title>
      <link>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13768#M10130</link>
      <description>&lt;P&gt;This solution worked.  We've configure this into the template and created several new machines with no problems.  &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2010 19:54:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Splunk-configured-with-new-VMs/m-p/13768#M10130</guid>
      <dc:creator>trent6</dc:creator>
      <dc:date>2010-05-20T19:54:07Z</dc:date>
    </item>
  </channel>
</rss>

