Splunk Search

Is it required to set a static ip on the localhost for Splunk with Universal Forwarder to work?

elsaddiq
Engager

I'm a student running the free Community Edition in my homelab. My host currently receives a dynamic IP. Is a static IP required or recommended? Thank you.

0 Karma

vishaltaneja070
Motivator

Hello @elsaddiq

For sending data from Forwarder to Indexer, you need to mention the IP or DNS name of the indexer, if the ip is changing then it will be a issue as data sending will be stopped. So recommended is to have a static ip.

jas_go
New Member

Is this still the case? I have an EC2 instance that has dynamic ips and I would like to set up a splunk forwarder. Am I still able to get the logs over to the correct data lake?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well... there is a possibility of defining an output using a short-ttl DNS name (dyn-DNS), it's not something I'd recommend. Static addresses definitely make your life easier.

0 Karma

Anam
Community Manager
Community Manager

Hi @elsaddiq

Did the answer by @vishaltaneja07011993 help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...