Getting Data In

Universal forwarder on dhcp address

vitki
Explorer

Hi

I have a Universal forwarder running on a host with the network configured as dhcp. In the etc/system/local/inputs.conf the host is or was the last dns name of the host. If the host restarts the ip / dns name change but the name in the inputs.conf stays the same. Is there a way to change the host setting in inputs.conf to be dynamic assigned? (for udp or tcp)

Any help will be appreciated.

0 Karma

vitki
Explorer

Well seems I am the only one with this prob.

I found a workaround to the problem. Just install a script on start up before Splunk starts up to clear the host and guid properties....

So every time the Splunk forwarder starts up it will repopulate the host field in the inputs.conf and guid field in the server.conf files.

As per Splunk Doc = http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Makeadfpartofasystemimage

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...