Splunk Cloud Platform

Splunk Cloud use static IP?

Michael_Carlisl
Explorer

I've noticed that in our splunkd.log file it will time out using the FQDN that comes with our spl file. It eventually finds an IP address to connect to (although it shoots out a lot of warnings that it cannot connect at first) and everything works fine. We have a FreeBSD instance that is never able to forward using the FQDN, and ONLY works with the IP address. The problem is that the IP seems to not be static, so whenever that IP changes, our forwarder stops working. Has anyone seen this before or know of a solution?

Best,
Michael

Tags (1)
0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Splunk Cloud instances are behind Elastic Load Balancers (ELB.) And depending on if you have a Single Instance or a Managed (Clustered stack), there is potential for IP addresses to be changed.

This means they are not static, nor can they be. (For the indexer(s).)

LGuinn's solution is best. However, I would be more concerned with why your instance isnt able to perform basic network name resolution. How does it access other services?

0 Karma

lguinn2
Legend

You could create an intermediate forwarder to connect to the Splunk Cloud. Have any "problematic" forwarders like your FreeBSD instance connect to the intermediate forwarder. The intermediate forwarder can be a Universal Forwarder, which creates less overhead than a heavy forwarder.

You might also open a support ticket and find out if you can get a static IP address assigned.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...