Getting Data In

Why does host name show up in Splunk Cloud in all caps, but Splunk UF is showing lower case name?

wvoegarcia
Engager

I am having an issue with the Host name showing up in all capital letters on Splunk Cloud, but the Splunk UF is showing its name in lower case for both host and the Splunk instance name. This is occurring on a Windows 2016 platform.

I have verified that the name is all lower case in the server.conf file and just for gee whiz, I ran the "splunk.exe clone-prep-clear-config" command on this server and nothing changed.  I have verified via the system screen and the command line that the servers name is lowercase.

I ran and IPconfig /all and it too is showing the host name as lower case and NETBIOS has been disabled on this server. Also using the Nbtstat commands I have validated that the NetBios is disabled on this server.

Not sure how to proceed from here. Any advice would be greatly appreciated.

Labels (1)
0 Karma
1 Solution

wvoegarcia
Engager

Thanks for your reply,

The issue appears with both “Host” and “host” and found no issues with the inputs.conf.  I forgot to add that I did run the btool and got no results their either.  To correct this issue, I went into the local/server.conf file and change it to an all Capital Name.  This changed the Instance name on the Splunk Universal Forwarder to all caps. 

I went one step further and ran the clone-prep-clear-config command, which changed the name back to all lower case.  So the server.conf was changed back to an all caps name.

Also, I have over 2600 servers that are reporting to my Splunk Cloud and this is the only server that we are having this issue with.  I am going to stick with the manual change we made to the server.conf file and chalk this one up to the every present Splunk Gremlin.

Thanks for your response

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

What exactly are you looking at when you check the Host name?  Is the field "Host" or "host" (they're not the same)?  Is this for all hosts or just some of them?

Have you checked the inputs.conf files on the problem host(s)?  Run this command to help isolate the problem setting:

splunk btool --debug inputs list | grep "\bhost"
---
If this reply helps you, Karma would be appreciated.
0 Karma

wvoegarcia
Engager

Thanks for your reply,

The issue appears with both “Host” and “host” and found no issues with the inputs.conf.  I forgot to add that I did run the btool and got no results their either.  To correct this issue, I went into the local/server.conf file and change it to an all Capital Name.  This changed the Instance name on the Splunk Universal Forwarder to all caps. 

I went one step further and ran the clone-prep-clear-config command, which changed the name back to all lower case.  So the server.conf was changed back to an all caps name.

Also, I have over 2600 servers that are reporting to my Splunk Cloud and this is the only server that we are having this issue with.  I am going to stick with the manual change we made to the server.conf file and chalk this one up to the every present Splunk Gremlin.

Thanks for your response

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...