Splunk Enterprise

SplunkUniversalForwarder instanceName = none

cjpote
Explorer

Some cloned Red Hat Enterprise Linux 7 systems show blank "Instance Name" values on my deployment server's Forwarder Management tab, and when executing ./splunk list deploy-clients, the forwarders instanceName value is shown as "none".
Where is the instanceName value set?

0 Karma

adonio
Ultra Champion

check /splunkforwarder/etc/system/local/inputs.conf and /splunkforwarder/etc.system/local/server.conf
hope it helps

0 Karma

cjpote
Explorer

Sorry, I should have mentioned that I already verified the "serverName = " value in $SPLUNK_HOME/etc/system/local/server.conf, and "host = " in $SPLUNK_HOME/etc/system/local/inputs.conf. They are both set to the same value returned by the "hostname" command on the system.

I also verified that "$SPLUNK_HOME/bin/splunk cmd btool [server|inputs] list --debug" shows the correct serverName and host values; but neither one of those shows an "instance(Name) = " value.

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...