Getting Data In

Change Splunk IP

ShaunBaker
Path Finder

How do I successfully change the Splunk instance (all in one indexer, search head, webUI etc) VM's IP address?

Since Splunk 7 - 8, the Splunk install automatically uses the VMWare admin interface making it so I can only log into Splunk via the VM.

I follow the Bind IP instructions here : https://docs.splunk.com/Documentation/Splunk/6.1.3/Admin/BindSplunktoanIP to get it to where I can now log into the webUI via the IP I specify, but this breaks Splunk. Upon reboot I get a 500 service not found. IP and ports are as specified when I reboot Splunk, but the webUI will no longer work and I have to restore from a snapshot.

token2
Path Finder

I'm fairly certain with Splunk 7.3.1 following the BindIP instructions brakes the webUI.

When I clear out the stanza to bind the IP I can log back into splunk again from within the VM (as Splunk is choosing the virbr0 interface for some reason).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...