Deployment Architecture

SHCluster replication overwrites hostname in $SPLUNK_HOME/etc/system/local/inputs.conf

SteveBowser
Explorer

Everytime we have to force replication on the SH nodes of a SH Cluster, the inputs.conf replicates and overwrites the hostname. Is there anyway to blacklist a .conf file by location to prevent it replicating when you do a forced resync of the SH nodes?

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
If I recall right SHC shouldn't replicate those files in etc/system/local . Those are host specific local files by default.

Are you absolutely sure that your host is defined in inputs.conf file under system/local instead of inside some app?
Can you check it from CLI with command "splunk btool inputs list --debug | egrep host"? Unfortunately this gives a lot entries, but you can see if there is also 'etc/system/local' on list.
0 Karma

SteveBowser
Explorer

Totally agreeing with you as this only happens on our ES SHC, and not our ITSI SHC. We have a work-around where we edit the $SPLUNK_HOME/etc/system/local/inputs.conf 
This will be looked into further after the holidays, so if I do find it, I'll be back on here.

0 Karma

SteveBowser
Explorer

I just did this from the /opt/splunk directory on all 3 SHC members, and the deployer:

grep --include=inputs.conf -rnw . -e "host ="

The only place where I see the hostname being in an inputs.conf is in $SPLUNK_HOME/etc/system/local, and $SPLUNK_HOME/var/run/splunk/confsnapshot/baselinelocal/inputs.conf

Kind of at a loss...

0 Karma

isoutamo
SplunkTrust
SplunkTrust
It could be like “host\s*=“.
The best way is use btool with —debug to see where it has defined.
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@SteveBowser  Checkout

inputs.conf

$decideOnStartup

server.conf 

hostnameOption = [ fullyqualifiedname | clustername | shortname ]







If this reply helps, Please Upvote.



If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
0 Karma

SteveBowser
Explorer

As we use specialized names for the host, this might not be an option, but we will be looking at this also. Like I mentioned to the other responder, after the holidays and we have a crude work-around. 

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...