Splunk Search

Bind forwarder to particular IP

msarro
Builder

Hey everyone. I am trying to bind the forwarding service to a particular IP because one of the boxes we are using as a source is multihomed. First, is this possible? Second, how would I go about doing it? The hosts in question run on both Solaris and Linux.

Tags (1)
0 Karma

David
Splunk Employee
Splunk Employee

For binding the listening service, you should use this: http://www.splunk.com/base/Documentation/latest/Admin/BindSplunktoanIP

For controlling the path taken by the forwarding service, I believe Splunk will just use the OS level networking, so you would implement that with a static route (e.g., the linux route command).

Does that answer your question?

msarro
Builder

I'm going to have to try it out, I'll let you know! 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...