Hello,
We have a forwarder with multiple ip address.
What is the procedure explicitly set the ip address on the forwarder to listen on.
Thanks,
Simon Mandy
Use the bind_ip configuration in splunk-launch.conf
See the spec file at : http://docs.splunk.com/Documentation/Splunk/6.2.2/Admin/Splunk-launchconf
I went to $SPLUNK_HOME/etc/splunk-launch.conf and added SPLUNK_BINDIP = xx.xx.xx.xx
Also created $SPLUNK_HOME/etc/system/local/web.conf with below entries,
[settings]
mgmtHostPort = xx.xx.xx.xx:8089
restarted the forwarder but still in $SPLUNK_HOME/var/log/splunk/splunkd.log I see below logs.
04-16-2015 03:47:08.374 -0400 INFO HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection__8089_xxxx-xxxx--external1-xxx.xx.xx_xxxxx_EDC24749-F321-48D1-86E5-43A959A42502
sim_tcr - did you ever figure out how the IP was being populated in the phonehome rui string?