Thanks for your reply, The issue appears with both “Host” and “host” and found no issues with the inputs.conf. I forgot to add that I did run the btool and got no results their either. To correct this issue, I went into the local/server.conf file and change it to an all Capital Name. This changed the Instance name on the Splunk Universal Forwarder to all caps. I went one step further and ran the clone-prep-clear-config command, which changed the name back to all lower case. So the server.conf was changed back to an all caps name. Also, I have over 2600 servers that are reporting to my Splunk Cloud and this is the only server that we are having this issue with. I am going to stick with the manual change we made to the server.conf file and chalk this one up to the every present Splunk Gremlin. Thanks for your response
... View more