Deployment Architecture

Deploy Server showing incorrect Deploy Client hostname:

ppacheco
Explorer

I am using splunk 4.3 in Amazon's ec2. I have used the "./splunk set servername" and restarted on all of the clients. But using "./splunk list deploy-clients" on the deploy server shows the ec2 internal hostname for all but a few hosts. A couple of outliers are properly showing the name as defined by "./splunk set servername", but I can't seem to figure out why about 5 percent of the hosts are working. On the deploy server, I've tried "./splunk refresh deploy-clients" with no change. I've tried resetting the servername as well as the default-hostname on the clients then refreshing on the deploy server, to no avail. I also confirmed that on both a working host and a non-working host the server.conf file looks the same.

Going to the logs, I see the entry in splunkd.log on the working host is like this:
05-09-2012 18:27:09.422 +0000 INFO ServerConfig - My hostname is "reportdb.us-east-1.foo.com".

On a non-working host is like this:
06-14-2012 21:26:58.769 +0000 INFO ServerConfig - My hostname is "ip-10-124-193-41".

How do I force the deploy server to see the desired hostname so that I can get server classes working?

Tags (2)
0 Karma

ppacheco
Explorer

I had it in my head that the "splunk set servername" was supposed to provide this name, but it does not. After some grinding, I discovered that the "My hostname is" mentioned above, comes from the system file /etc/hostname. So I used the UNIX command "hostname myname.splunk.com" to set the hostname, restarted the splunkforwarder on the client, then ran "./splunk refresh deploy-clients" on the deploy server and it worked. I am now able to use host name directives in serverclass.conf.

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...