Splunk Search

Is it required to set a static ip on the localhost for Splunk with Universal Forwarder to work?

elsaddiq
Engager

I'm a student running the free Community Edition in my homelab. My host currently receives a dynamic IP. Is a static IP required or recommended? Thank you.

0 Karma

vishaltaneja070
Motivator

Hello @elsaddiq

For sending data from Forwarder to Indexer, you need to mention the IP or DNS name of the indexer, if the ip is changing then it will be a issue as data sending will be stopped. So recommended is to have a static ip.

jas_go
New Member

Is this still the case? I have an EC2 instance that has dynamic ips and I would like to set up a splunk forwarder. Am I still able to get the logs over to the correct data lake?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well... there is a possibility of defining an output using a short-ttl DNS name (dyn-DNS), it's not something I'd recommend. Static addresses definitely make your life easier.

0 Karma

Anam
Community Manager
Community Manager

Hi @elsaddiq

Did the answer by @vishaltaneja07011993 help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...