<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to change hostname for the splunk windows universal forwarder? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676020#M231250</link>
    <description>&lt;P&gt;I found a serverName = $COMPUTERNAME in the path blow:&lt;/P&gt;&lt;P&gt;\Peogrm Files\splunkuniversalforwarder\etc\system\default \server.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed this parameter and also added [default] host = mydashboard in config file , it didn't work&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2024 09:01:39 GMT</pubDate>
    <dc:creator>chakavak</dc:creator>
    <dc:date>2024-01-31T09:01:39Z</dc:date>
    <item>
      <title>How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675852#M231211</link>
      <description>&lt;P&gt;I have installed splunk and added windows systems to splunk through universal forwarder, but I have a problem with default system names, these names confusing me when I check their status, I want to consider alias name or rename hostname so that I diagnose system with it's name in search.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I want to change hostname "WIN-KLV1NNUJO8P" to "mydashboard" .&lt;/P&gt;&lt;P&gt;Please help me, I can't find answer for this problem and solutions that I found in the internet not working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 06:47:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675852#M231211</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-01-30T06:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675854#M231213</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264454"&gt;@chakavak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you could manually rename hostaname in $SPLUNK_HOME\etc\system\local\server.conf and $SPLUNK_HOME\etc\system\local\inputs.conf of your forwarder to have thes values in your logs.&lt;/P&gt;&lt;P&gt;Otherwise, you could rename it with a calculated field at search time.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 06:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675854#M231213</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-30T06:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675856#M231214</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply, I changed the hostname in server.conf, but in forwarder inputs.conf not there in the mentioned path, I have outputs.conf!!!!&lt;/P&gt;&lt;P&gt;It also doesn't work when I just change the server.conf file.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 06:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675856#M231214</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-01-30T06:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675858#M231215</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264454"&gt;@chakavak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;outputs.con must not be changed!&lt;/P&gt;&lt;P&gt;did you restarted Splunk on the UF after change?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 07:25:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675858#M231215</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-30T07:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675859#M231216</link>
      <description>&lt;P&gt;Yes, I restarted the SplunkForwarder service&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 07:37:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675859#M231216</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-01-30T07:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675862#M231217</link>
      <description>&lt;P&gt;Excuse me, can you tell me how to use calculated field for renaming host (for example change "WIN-KLV1NNUJO8P" to "mydashboard"? I'm new to splunk and learning&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:31:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675862#M231217</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-01-30T08:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675864#M231219</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264454"&gt;@chakavak&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you share your $SPLUNK_HOME\etc/system\local\server.conf ?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675864#M231219</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-30T08:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675865#M231220</link>
      <description>&lt;P&gt;[general]&lt;/P&gt;&lt;P&gt;serverName = mydashboard&lt;/P&gt;&lt;P&gt;pass4SymmKey = $7$Jte1qcrLi+3xY2ipx1brJChXbKmr+9ZYKthpA0Edywk92IjolIKAEg==&lt;/P&gt;&lt;P&gt;[sslConfig]&lt;/P&gt;&lt;P&gt;sslPassword = $7$+6pIzsRauFB5hevEHOxTpjcV3OW9bakXS9oFXZYydFHaX98N1irSjg==&lt;/P&gt;&lt;P&gt;[lmpool:auto_generated_pool_forwarder]&lt;/P&gt;&lt;P&gt;description = auto_generated_pool_forwarder&lt;/P&gt;&lt;P&gt;peers = *&lt;/P&gt;&lt;P&gt;quota = MAX&lt;/P&gt;&lt;P&gt;stack_id = forwarder&lt;/P&gt;&lt;P&gt;[lmpool:auto_generated_pool_free]&lt;/P&gt;&lt;P&gt;description = auto_generated_pool_free&lt;/P&gt;&lt;P&gt;peers = *&lt;/P&gt;&lt;P&gt;quota = MAX&lt;/P&gt;&lt;P&gt;stack_id = free&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:50:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675865#M231220</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-01-30T08:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675866#M231221</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264454"&gt;@chakavak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's correct and it should be sufficient.&lt;/P&gt;&lt;P&gt;Anyway, please add in $SPLUNK_HOME\etc\system\local the inpus.conf file containing the following stanza:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[default]
host = mydashboard&lt;/LI-CODE&gt;&lt;P&gt;and restart Splunk on the Universal Forwarder.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 09:09:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675866#M231221</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-30T09:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675990#M231246</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I tried this solution, but it didn't work&lt;span class="lia-unicode-emoji" title=":slightly_frowning_face:"&gt;🙁&lt;/span&gt; I think Splunk reads the computer name from another file that has a higher priority &lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 04:54:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675990#M231246</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-01-31T04:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675995#M231247</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264454"&gt;@chakavak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;maybe there's another server.conf, please try:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;cd \Program Files\splunkuniversalforwarder\bin
splunk btool server list --debug &amp;gt; my_server.txt&lt;/LI-CODE&gt;&lt;P&gt;and search in&amp;nbsp;my_server.txt if there's another "hostname" parameter in another server.conf file.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 06:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/675995#M231247</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-31T06:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676020#M231250</link>
      <description>&lt;P&gt;I found a serverName = $COMPUTERNAME in the path blow:&lt;/P&gt;&lt;P&gt;\Peogrm Files\splunkuniversalforwarder\etc\system\default \server.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed this parameter and also added [default] host = mydashboard in config file , it didn't work&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 09:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676020#M231250</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-01-31T09:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676026#M231253</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264454"&gt;@chakavak&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the default folder has a minor priority than local and you cannot modify it.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[default] host = mydashboard must be inserted in inputs.conf not in server.conf.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Open a case to Splunk Support for behavior non aligned with documentation, sending them a diag from that UF.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2024 09:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676026#M231253</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-01-31T09:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676454#M231363</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;&lt;P&gt;OK. Thanks for your advice.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 05:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676454#M231363</guid>
      <dc:creator>chakavak</dc:creator>
      <dc:date>2024-02-03T05:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to change hostname for the splunk windows universal forwarder?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676500#M231370</link>
      <description>&lt;P&gt;As you are talking about windows, it might be more complicated than that.&lt;/P&gt;&lt;P&gt;By default TA_windows contains tranforms which extract the host field from the event itself so even if you set it to something in the UF's configuration, it will be overwritten by the value of ComputerName of Computer field from the event. (and that makes sense because often windows event are not generated on the host they are being ingested from - WEF is a commonly used mechanism to forward events within a windows environment to a single collector node from which it is pulled by UF).&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 13:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-change-hostname-for-the-splunk-windows-universal/m-p/676500#M231370</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-02-04T13:23:21Z</dc:date>
    </item>
  </channel>
</rss>

