Getting Data In

How to configure multiple host names in a single inputs.conf file, and push this to all servers in a server class via deployment server?

sujith_usha_kum
Explorer

Hi All,

We have a deployment server configured in our server.
We want to push a single inputs.conf file to all the servers in the server class.

Please help me on how to use host= in the inputs.conf file, where we have multiple servers under one server class.

thanks

0 Karma

ddrillic
Ultra Champion

Keep in mind please that the hosts are specified in etc/system/local/serverclass.conf.

How many apps do you have under etc/deployment-apps?

0 Karma

sujith_usha_kum
Explorer

Thanks.

etc/system/local/serverclass.conf is to white and blacklist the servers under each serverclass is it?
But my requirement is to use one input.conf file for a set of servers under the server class.
So do i need to specify the "host=" keyword to mention the client names?
If yes, how to specify multiple client name under "host="

I have 10 apps under etc/deployment-apps

0 Karma

ddrillic
Ultra Champion

I see, quite often we simply don't specify the host in inputs.conf and Splunk will determine what it is based on the machine's info. It's pretty good and we have been using it in this way for a couple of years. One issue we are running into is the fact that some hosts define their name using a full domain name and some don't. But if you don't have this issue, you might rely on Splunk for that...

0 Karma

sujith_usha_kum
Explorer

Thanks ddrillic. I will try not using host in inputs.conf

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...