Splunk Enterprise

Need a help in changing host name of/in Splunk

satyaallaparthi
Communicator

Hello, 

 

How can I change the host name displaying in Splunk with out changing /etc/hostname in linux.

I did changed in system/local/inputs.conf under default and /local/server.conf under general. 

 

But nothing has helped me. I am trying to achieve SAML integration with Splunk for SSO. I am getting an error, since my linux host name starts with numbers.

 

Please do help me. 

 

 

Thanks in Advance. 

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

Did you mean to say after changing hostname in system/local/inputs.conf and server.conf still seeing old name?

If yes, did you restart splunk after changing host value in above two places?

can you confirm where exactly are you seeing old name?

 

————————————
If this helps, give a like below.
0 Karma

satyaallaparthi
Communicator

Did you mean to say after changing hostname in system/local/inputs.conf and server.conf still seeing old name? Yes, I am seeing instance name is changed, but not the host name reporting to deployment server 

If yes, did you restart splunk after changing host value in above two places? Yes 

can you confirm where exactly are you seeing old name? I am seeing the Linux server name in deployment server -->forwarder management-->clients, which start with number like 01.splunk and 02.splunk (I want to take out the number and keep in the middle Ex: splunk.01 and splunk.02, with out changing linux host name)

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Can you verify host value under system/local/inputs.conf in deployment client?

you can follow below steps:

splunk set servername “servername”

splunk set default-host “servername”

remove $SPLUNK_HOME/etc/instance.cfg

splunk restart

Note: dont copy paste “ quotes may not work as I am typing from my phone.

————————————
If this helps, give a like below.
0 Karma

satyaallaparthi
Communicator

I changed splunk set default-hostname “servername” and I tried all possiblities, that I can. But nothing has helped me and still displaying the linux host name in deployment server.

 

Even though, I am changing inputs.conf to another server name.. it's going back to the server name again after restart(I am not using any conf management tool for the inputs)

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...