Getting Data In

Host name is not updating in the web app

deegupta
New Member

I had splunk forwarder setup at the server machines and the logs are being forwarded to splunk server fine. I can also view all the logs in the web app.

However, since my server setup has two kinds of servers, i renamed one of the server component's host name. To do this, i edited inputs.conf file and changed the Host value to the desired string. After doing this I restarted the splunk service.

But the newly added Host is not appearing in the web app. Is there something else to be done here? Please help.

Tags (1)
0 Karma

deegupta
New Member

Found the issue here. I had multiple instances of the same host type and missed updating the inputs.conf for one instance. The logs were coming in splunk but host name was not updating.

After updating the inputs.conf for all the instances, everything is working fine now.

Thanks every one.

0 Karma

kml_uvce
Builder

If you have added Host name in inputs.conf from forwarder side and restarted , ideally host name should come in Web app, please check any errors or new logs are coming into splunk web app.

kamal singh bisht
0 Karma

HiroshiSatoh
Champion

Did you check the log? I think error and are on the log settings if wrong.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...