<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk search and changed domaincontroller name in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-search-and-changed-domaincontroller-name/m-p/104027#M26905</link>
    <description>&lt;P&gt;thanks, but thats not a solution to my problem&lt;BR /&gt;
i have searched all config files on my splunk system, but there is nowhere a hardcoded "WIN-2LUN2OJR0JR" in it&lt;/P&gt;</description>
    <pubDate>Fri, 18 Oct 2013 11:06:00 GMT</pubDate>
    <dc:creator>ESIMatNeforce</dc:creator>
    <dc:date>2013-10-18T11:06:00Z</dc:date>
    <item>
      <title>splunk search and changed domaincontroller name</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-search-and-changed-domaincontroller-name/m-p/104025#M26903</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have recently changed the computername of my Domaincontroller. When I make a splunk search with "failed password" I get the logs with some attributes of the old hostname and some of the new one:&lt;/P&gt;

&lt;P&gt;dest_nt_host     W2012R2SrvDC.splunktest.local&lt;BR /&gt;&lt;BR /&gt;
dvc              WIN-2LUN2OJR0JR&lt;BR /&gt;&lt;BR /&gt;
dvc_nt_host      WIN-2LUN2OJR0JR&lt;BR /&gt;&lt;BR /&gt;
host             WIN-2LUN2OJR0JR&lt;/P&gt;

&lt;P&gt;The new computername is W2012R2SrvDC. Why does Splunk still has the old computername in the found logs? (the logs are newly created) and how can I fix this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-search-and-changed-domaincontroller-name/m-p/104025#M26903</guid>
      <dc:creator>ESIMatNeforce</dc:creator>
      <dc:date>2020-09-28T14:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: splunk search and changed domaincontroller name</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-search-and-changed-domaincontroller-name/m-p/104026#M26904</link>
      <description>&lt;P&gt;Sounds like on the initial setup of this host you have a constant value for the host field value in the Splunk configuration and you just need to change that.&lt;/P&gt;

&lt;P&gt;In the inputs.conf do you have an entry assigning the hostname like this?&lt;/P&gt;

&lt;P&gt;[monitor:///whatever/log1]&lt;BR /&gt;
host = abc.mydomain.com&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2013 13:22:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-search-and-changed-domaincontroller-name/m-p/104026#M26904</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-10-17T13:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: splunk search and changed domaincontroller name</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-search-and-changed-domaincontroller-name/m-p/104027#M26905</link>
      <description>&lt;P&gt;thanks, but thats not a solution to my problem&lt;BR /&gt;
i have searched all config files on my splunk system, but there is nowhere a hardcoded "WIN-2LUN2OJR0JR" in it&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2013 11:06:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-search-and-changed-domaincontroller-name/m-p/104027#M26905</guid>
      <dc:creator>ESIMatNeforce</dc:creator>
      <dc:date>2013-10-18T11:06:00Z</dc:date>
    </item>
  </channel>
</rss>

