Splunk Cloud Platform

Splunk Cloud use static IP?

Michael_Carlisl
Explorer

I've noticed that in our splunkd.log file it will time out using the FQDN that comes with our spl file. It eventually finds an IP address to connect to (although it shoots out a lot of warnings that it cannot connect at first) and everything works fine. We have a FreeBSD instance that is never able to forward using the FQDN, and ONLY works with the IP address. The problem is that the IP seems to not be static, so whenever that IP changes, our forwarder stops working. Has anyone seen this before or know of a solution?

Best,
Michael

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Splunk Cloud instances are behind Elastic Load Balancers (ELB.) And depending on if you have a Single Instance or a Managed (Clustered stack), there is potential for IP addresses to be changed.

This means they are not static, nor can they be. (For the indexer(s).)

LGuinn's solution is best. However, I would be more concerned with why your instance isnt able to perform basic network name resolution. How does it access other services?

0 Karma

lguinn2
Legend

You could create an intermediate forwarder to connect to the Splunk Cloud. Have any "problematic" forwarders like your FreeBSD instance connect to the intermediate forwarder. The intermediate forwarder can be a Universal Forwarder, which creates less overhead than a heavy forwarder.

You might also open a support ticket and find out if you can get a static IP address assigned.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...