Hello,
How can I change the host name displaying in Splunk with out changing /etc/hostname in linux.
I did changed in system/local/inputs.conf under default and /local/server.conf under general.
But nothing has helped me. I am trying to achieve SAML integration with Splunk for SSO. I am getting an error, since my linux host name starts with numbers.
Please do help me.
Thanks in Advance.
Did you mean to say after changing hostname in system/local/inputs.conf and server.conf still seeing old name?
If yes, did you restart splunk after changing host value in above two places?
can you confirm where exactly are you seeing old name?
Did you mean to say after changing hostname in system/local/inputs.conf and server.conf still seeing old name? Yes, I am seeing instance name is changed, but not the host name reporting to deployment server
If yes, did you restart splunk after changing host value in above two places? Yes
can you confirm where exactly are you seeing old name? I am seeing the Linux server name in deployment server -->forwarder management-->clients, which start with number like 01.splunk and 02.splunk (I want to take out the number and keep in the middle Ex: splunk.01 and splunk.02, with out changing linux host name)
Can you verify host value under system/local/inputs.conf in deployment client?
you can follow below steps:
splunk set servername “servername”
splunk set default-host “servername”
remove $SPLUNK_HOME/etc/instance.cfg
splunk restart
Note: dont copy paste “ quotes may not work as I am typing from my phone.
I changed splunk set default-hostname “servername” and I tried all possiblities, that I can. But nothing has helped me and still displaying the linux host name in deployment server.
Even though, I am changing inputs.conf to another server name.. it's going back to the server name again after restart(I am not using any conf management tool for the inputs)