Getting Data In

Why is DNS lookup failing during indexing for 2 hosts?

bdf0506
Path Finder

I just moved my Splunk indexer from one server to another. A few bumps in the road, but everything seems to be working now, except for that fact that two hosts will not resolve in DNS, so Splunk is indexing them as IP addresses instead. They are located on a different network than the Splunk indexer, but they still resolve in DNS. Old server was running CentOS, new server is running Ubuntu 18.04. All other hosts that I index run Splunk universal forwarder, and when those logs make it to my indexer, they are already coming in with hostnames and not IPs.

The traffic is coming on typical udp/514, one from a cisco ASA, the other from a Cisco Switch. Prior to moving the Splunk instance, hostnames resolved fine. The DNS server is the same as it was before.

They resolve fine with nslookup:

[root@splunk ~]$ nslookup 192.168.50.2
2.50.168.192.in-addr.arpa       name = Switch.

Authoritative answers can be found from:

[root@splunk ~]$ nslookup 192.168.10.50
50.10.168.192.in-addr.arpa      name = CiscoASA.

Authoritative answers can be found from:

alt text

Any idea why these wouldn't resolve with Splunk indexer?

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...