Getting Data In

Where is my host data coming from?

seanlon11
Path Finder

I have about 50 forwarders in my environment. Somewhere I have screwed up, and included the same set of host data twice, but one with a typo. I went to the inputs.conf and looked at the stanza, and I only have the correctly spelled host. So somewhere I have messed something up.

How can I tell where a particular host's data is coming from? (preferrably the IP address)

Thanks, Sean

Tags (1)
0 Karma

seanlon11
Path Finder

OK, I found it by looking through the splunkd.log file.

I looked for the host in question, and looked for the connections around the containing entry. That led me to the inputs.conf file that had the mistake.

Hope this helps someone else in the distant future.

  • Sean
0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...