Getting Data In

Universal forwarder on dhcp address

vitki
Explorer

Hi

I have a Universal forwarder running on a host with the network configured as dhcp. In the etc/system/local/inputs.conf the host is or was the last dns name of the host. If the host restarts the ip / dns name change but the name in the inputs.conf stays the same. Is there a way to change the host setting in inputs.conf to be dynamic assigned? (for udp or tcp)

Any help will be appreciated.

0 Karma

vitki
Explorer

Well seems I am the only one with this prob.

I found a workaround to the problem. Just install a script on start up before Splunk starts up to clear the host and guid properties....

So every time the Splunk forwarder starts up it will repopulate the host field in the inputs.conf and guid field in the server.conf files.

As per Splunk Doc = http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Makeadfpartofasystemimage

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...