Getting Data In

Splunk not reconignizing DNS name

ATT-CommonServi
New Member

The VM server is using the local name to bind to the application interface, thus data is being sent over on eth1-0, and it seems splunk is looking for the data on eth0. We don't get the dns match in the whitelist. Is there a way to configure splunk agent where it will send data on eth1-0 instead of eth1-0.

Tags (1)
0 Karma

pb0543
Explorer

The splunk universal fowarder(on the host VM) is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

pb0543
Explorer

The splunk universal fowarder is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'm not sure I understand the issue precisely, but perhaps my clarification questions may help someone else think through the answer:

Splunk agent - you mean a Universal Forwarder? And it's sending data out the wrong interface? Or it's listening on the wrong interface? Two possible answers below, then, depending on which is the problem.

If the latter - it's not listening on the right interface:
Perhaps see
How do I bind Splunk to a specific interface?

If the former - it's sending data OUT the wrong interface:
It could be the same problem as above (see link), or it could be a routing issue on the local machine to me. If my computer has two interfaces and I want certain traffic to travel out a particular one of the two, well, the easiest way is to make sure I have my default (or the appropriate) route set to send traffic over that interface. Usually, the reason to do this is because you have more than one interface and they're on different subnets/vlans. And, usually, in that case, the system does it based on the route masks.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...