Getting Data In

Universal forwarder on dhcp address

vitki
Explorer

Hi

I have a Universal forwarder running on a host with the network configured as dhcp. In the etc/system/local/inputs.conf the host is or was the last dns name of the host. If the host restarts the ip / dns name change but the name in the inputs.conf stays the same. Is there a way to change the host setting in inputs.conf to be dynamic assigned? (for udp or tcp)

Any help will be appreciated.

0 Karma

vitki
Explorer

Well seems I am the only one with this prob.

I found a workaround to the problem. Just install a script on start up before Splunk starts up to clear the host and guid properties....

So every time the Splunk forwarder starts up it will repopulate the host field in the inputs.conf and guid field in the server.conf files.

As per Splunk Doc = http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Makeadfpartofasystemimage

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...