Splunk Enterprise

Need a help in changing host name of/in Splunk

satyaallaparthi
Communicator

Hello, 

 

How can I change the host name displaying in Splunk with out changing /etc/hostname in linux.

I did changed in system/local/inputs.conf under default and /local/server.conf under general. 

 

But nothing has helped me. I am trying to achieve SAML integration with Splunk for SSO. I am getting an error, since my linux host name starts with numbers.

 

Please do help me. 

 

 

Thanks in Advance. 

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

Did you mean to say after changing hostname in system/local/inputs.conf and server.conf still seeing old name?

If yes, did you restart splunk after changing host value in above two places?

can you confirm where exactly are you seeing old name?

 

————————————
If this helps, give a like below.
0 Karma

satyaallaparthi
Communicator

Did you mean to say after changing hostname in system/local/inputs.conf and server.conf still seeing old name? Yes, I am seeing instance name is changed, but not the host name reporting to deployment server 

If yes, did you restart splunk after changing host value in above two places? Yes 

can you confirm where exactly are you seeing old name? I am seeing the Linux server name in deployment server -->forwarder management-->clients, which start with number like 01.splunk and 02.splunk (I want to take out the number and keep in the middle Ex: splunk.01 and splunk.02, with out changing linux host name)

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Can you verify host value under system/local/inputs.conf in deployment client?

you can follow below steps:

splunk set servername “servername”

splunk set default-host “servername”

remove $SPLUNK_HOME/etc/instance.cfg

splunk restart

Note: dont copy paste “ quotes may not work as I am typing from my phone.

————————————
If this helps, give a like below.
0 Karma

satyaallaparthi
Communicator

I changed splunk set default-hostname “servername” and I tried all possiblities, that I can. But nothing has helped me and still displaying the linux host name in deployment server.

 

Even though, I am changing inputs.conf to another server name.. it's going back to the server name again after restart(I am not using any conf management tool for the inputs)

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...