Getting Data In

Splunk not reconignizing DNS name

ATT-CommonServi
New Member

The VM server is using the local name to bind to the application interface, thus data is being sent over on eth1-0, and it seems splunk is looking for the data on eth0. We don't get the dns match in the whitelist. Is there a way to configure splunk agent where it will send data on eth1-0 instead of eth1-0.

Tags (1)
0 Karma

pb0543
Explorer

The splunk universal fowarder(on the host VM) is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

pb0543
Explorer

The splunk universal fowarder is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'm not sure I understand the issue precisely, but perhaps my clarification questions may help someone else think through the answer:

Splunk agent - you mean a Universal Forwarder? And it's sending data out the wrong interface? Or it's listening on the wrong interface? Two possible answers below, then, depending on which is the problem.

If the latter - it's not listening on the right interface:
Perhaps see
How do I bind Splunk to a specific interface?

If the former - it's sending data OUT the wrong interface:
It could be the same problem as above (see link), or it could be a routing issue on the local machine to me. If my computer has two interfaces and I want certain traffic to travel out a particular one of the two, well, the easiest way is to make sure I have my default (or the appropriate) route set to send traffic over that interface. Usually, the reason to do this is because you have more than one interface and they're on different subnets/vlans. And, usually, in that case, the system does it based on the route masks.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...