Hello @elsaddiq
For sending data from Forwarder to Indexer, you need to mention the IP or DNS name of the indexer, if the ip is changing then it will be a issue as data sending will be stopped. So recommended is to have a static ip.
Is this still the case? I have an EC2 instance that has dynamic ips and I would like to set up a splunk forwarder. Am I still able to get the logs over to the correct data lake?
Well... there is a possibility of defining an output using a short-ttl DNS name (dyn-DNS), it's not something I'd recommend. Static addresses definitely make your life easier.
Hi @elsaddiq
Did the answer by @vishaltaneja07011993 help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback.
Thanks!