Getting Data In

Splunk not reconignizing DNS name

ATT-CommonServi
New Member

The VM server is using the local name to bind to the application interface, thus data is being sent over on eth1-0, and it seems splunk is looking for the data on eth0. We don't get the dns match in the whitelist. Is there a way to configure splunk agent where it will send data on eth1-0 instead of eth1-0.

Tags (1)
0 Karma

pb0543
Explorer

The splunk universal fowarder(on the host VM) is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

pb0543
Explorer

The splunk universal fowarder is looking for data on eth0, but the host vm is sending data to the search head/indexers on eth1-0. For instance splunk is looking for a dns name of dsvtxvCaads01, and the host is sending dsvtxvCaads01-eth1-0.

0 Karma

Richfez
SplunkTrust
SplunkTrust

I'm not sure I understand the issue precisely, but perhaps my clarification questions may help someone else think through the answer:

Splunk agent - you mean a Universal Forwarder? And it's sending data out the wrong interface? Or it's listening on the wrong interface? Two possible answers below, then, depending on which is the problem.

If the latter - it's not listening on the right interface:
Perhaps see
How do I bind Splunk to a specific interface?

If the former - it's sending data OUT the wrong interface:
It could be the same problem as above (see link), or it could be a routing issue on the local machine to me. If my computer has two interfaces and I want certain traffic to travel out a particular one of the two, well, the easiest way is to make sure I have my default (or the appropriate) route set to send traffic over that interface. Usually, the reason to do this is because you have more than one interface and they're on different subnets/vlans. And, usually, in that case, the system does it based on the route masks.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...