Getting Data In

Change Splunk IP

ShaunBaker
Path Finder

How do I successfully change the Splunk instance (all in one indexer, search head, webUI etc) VM's IP address?

Since Splunk 7 - 8, the Splunk install automatically uses the VMWare admin interface making it so I can only log into Splunk via the VM.

I follow the Bind IP instructions here : https://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/BindSplunktoanIP to get it to where I can now log into the webUI via the IP I specify, but this breaks Splunk. Upon reboot I get a 500 service not found. IP and ports are as specified when I reboot Splunk, but the webUI will no longer work and I have to restore from a snapshot.

token2
Path Finder

I'm fairly certain with Splunk 7.3.1 following the BindIP instructions brakes the webUI.

When I clear out the stanza to bind the IP I can log back into splunk again from within the VM (as Splunk is choosing the virbr0 interface for some reason).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...