Getting Data In

Universal forwarder on dhcp address



I have a Universal forwarder running on a host with the network configured as dhcp. In the etc/system/local/inputs.conf the host is or was the last dns name of the host. If the host restarts the ip / dns name change but the name in the inputs.conf stays the same. Is there a way to change the host setting in inputs.conf to be dynamic assigned? (for udp or tcp)

Any help will be appreciated.

0 Karma


Well seems I am the only one with this prob.

I found a workaround to the problem. Just install a script on start up before Splunk starts up to clear the host and guid properties....

So every time the Splunk forwarder starts up it will repopulate the host field in the inputs.conf and guid field in the server.conf files.

As per Splunk Doc =

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!