How to change 127.0.0.1\test -> 192.168.1.5 ?
p.s. Linux (ubuntu 14.04) \ splunk enterprise
I need help, those who have still any ideas?
have you tried the option i have given above? by updating splunk-launch.conf?
Answer from renjith.nair is perfectly correct. But what I would do in an enteprise/corporate system is to create a separate app with various "splunk" web configurations and then put entry into the "local" of it.
eg of new app: myapp_prod_web_confs
put an entry into "myapp_prod_web_confs/local/web.conf" and put your entries into that. Copy the app (or push the app) and restart
koshyk
Understood nothing...
p.s. Me have splunk enterprise.
If you want to bind your splunk instance to a particular ip rather than bind to default, then you can change it by setting SPLUNK_BINDIP
parameter in splunk-launch.conf
in etc folder of your splunk installation.
CAUTION : When using this setting you must update mgmtHostPort in web.conf to match, or the command line and splunkweb will not know how to reach splunkd.
SPLUNK_BINDIP=<ip address>
* Specifies an interface that splunkd and splunkweb should bind to, as
opposed to binding to the default for the local operating system.
* If unset, Splunk makes no specific request to the operating system when
binding to ports/opening a listening socket. This means it effectively
binds to '*'; i.e. an unspecified bind. The exact result of this is
controlled by operating system behavior and configuration.
* NOTE: When using this setting you must update mgmtHostPort in web.conf to
match, or the command line and splunkweb will not know how to
reach splunkd.
* For splunkd, this sets both the management port and the receiving ports
(from forwarders).
* Useful for a host with multiple IP addresses, either to enable
access or restrict access; though firewalling is typically a superior
method of restriction.
* Overrides the Splunkweb-specific web.conf/[settings]/server.socket_host
param; the latter is preferred when SplunkWeb behavior is the focus.
* Defaults to unset.
README ? conf.spec?
Can splunk-launch.conf move in /opt/splunk/etc ?
Yes the location of splunk-launch.conf is in /opt/splunk/etc/.
Reference : http://docs.splunk.com/Documentation/Splunk/6.4.3/Admin/Splunk-launchconf#splunk-launch.conf.spec
# Note: this conf file is different from most splunk conf files. There is
# only one in the whole system, located at
# $SPLUNK_HOME/etc/splunk-launch.conf; further, there are no stanzas,
# explicit or implicit. Finally, any splunk-launch.conf files in
# etc/apps/... or etc/users/... will be ignored