Getting Data In

Splunk not reconignizing DNS name

ATT-CommonServi
New Member

The VM server is using the local name to bind to the application interface, thus data is being sent over on eth1-0, and it seems splunk is looking for the data on eth0. We don't get the dns match in the whitelist. Is there a way to configure splunk agent where it will send data on eth1-0 instead of eth1-0.

Tags (1)
0 Karma

pb0543
Explorer

The splunk universal fowarder(on the host VM) is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

pb0543
Explorer

The splunk universal fowarder is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'm not sure I understand the issue precisely, but perhaps my clarification questions may help someone else think through the answer:

Splunk agent - you mean a Universal Forwarder? And it's sending data out the wrong interface? Or it's listening on the wrong interface? Two possible answers below, then, depending on which is the problem.

If the latter - it's not listening on the right interface:
Perhaps see
How do I bind Splunk to a specific interface?

If the former - it's sending data OUT the wrong interface:
It could be the same problem as above (see link), or it could be a routing issue on the local machine to me. If my computer has two interfaces and I want certain traffic to travel out a particular one of the two, well, the easiest way is to make sure I have my default (or the appropriate) route set to send traffic over that interface. Usually, the reason to do this is because you have more than one interface and they're on different subnets/vlans. And, usually, in that case, the system does it based on the route masks.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...