Getting Data In

Splunk not reconignizing DNS name

ATT-CommonServi
New Member

The VM server is using the local name to bind to the application interface, thus data is being sent over on eth1-0, and it seems splunk is looking for the data on eth0. We don't get the dns match in the whitelist. Is there a way to configure splunk agent where it will send data on eth1-0 instead of eth1-0.

Tags (1)
0 Karma

pb0543
Explorer

The splunk universal fowarder(on the host VM) is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

pb0543
Explorer

The splunk universal fowarder is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'm not sure I understand the issue precisely, but perhaps my clarification questions may help someone else think through the answer:

Splunk agent - you mean a Universal Forwarder? And it's sending data out the wrong interface? Or it's listening on the wrong interface? Two possible answers below, then, depending on which is the problem.

If the latter - it's not listening on the right interface:
Perhaps see
How do I bind Splunk to a specific interface?

If the former - it's sending data OUT the wrong interface:
It could be the same problem as above (see link), or it could be a routing issue on the local machine to me. If my computer has two interfaces and I want certain traffic to travel out a particular one of the two, well, the easiest way is to make sure I have my default (or the appropriate) route set to send traffic over that interface. Usually, the reason to do this is because you have more than one interface and they're on different subnets/vlans. And, usually, in that case, the system does it based on the route masks.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...