Getting Data In

Why is my Splunk Forwarder showing up as "$COMPUTERNAME"?

tmontney
Builder

I used the variable "$COMPUTERNAME" in my app's inputs.conf file. For all the PCs that got it, it's reporting their computer name, as expected. The only one that's a problem is my computer. For a while, I wasn't seeing any data for it. That's until I realized, it was sending data under the host $COMPUTERNAME. I ran "splunk show servername" and it shows the right host name.

0 Karma
1 Solution

tmontney
Builder

By not specifying a host value, Splunk UF will automatically send the correct hostname.

View solution in original post

0 Karma

tmontney
Builder

By not specifying a host value, Splunk UF will automatically send the correct hostname.

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

When Splunk starts up for the first time, it writes a new inputs.conf in the $SPLUNK_HOME/etc/system/local subdirectory. This inputs.conf contains just a [default] section like you've described above, with the host set to the "discovered" name of the system. If you are looking to create a system image:

http://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Integrateauniversalforwarderontoasystemimage

tmontney
Builder

I'm not actually trying to create a system image (although I might in the future). I simply created an app on the Splunk server, and deployed it to existing clients. Clients are only referencing the app, not the /etc/system/local conf (that's my intention anyway). Since this is going out automatically, the hostname needs to be a variable. This worked for all laptops except one (my own).

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...