Getting Data In

Universal forwarder on dhcp address

vitki
Explorer

Hi

I have a Universal forwarder running on a host with the network configured as dhcp. In the etc/system/local/inputs.conf the host is or was the last dns name of the host. If the host restarts the ip / dns name change but the name in the inputs.conf stays the same. Is there a way to change the host setting in inputs.conf to be dynamic assigned? (for udp or tcp)

Any help will be appreciated.

0 Karma

vitki
Explorer

Well seems I am the only one with this prob.

I found a workaround to the problem. Just install a script on start up before Splunk starts up to clear the host and guid properties....

So every time the Splunk forwarder starts up it will repopulate the host field in the inputs.conf and guid field in the server.conf files.

As per Splunk Doc = http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Makeadfpartofasystemimage

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...