I am attempting to setup Splunk on a VM that will become a VM template. I have run sysprep and made it a template. I create a new VM from the template, and it receives new machine name and IP address.
The problem is that when it reports to Splunk, it has shows up under the old Hostname entry. I see current entries that state :
Host: oldName , Computername: oldName
and other entries that state
Host: oldName, Computername: newName
We are forwarding Windows event logs to a master Listener.
I see at least 3 places where the machine name is configured. Inputs.conf and 2 different server.conf files.
What is the best way for us to automate this?
... View more