Getting Data In

Why is my Splunk Forwarder showing up as "$COMPUTERNAME"?

tmontney
Builder

I used the variable "$COMPUTERNAME" in my app's inputs.conf file. For all the PCs that got it, it's reporting their computer name, as expected. The only one that's a problem is my computer. For a while, I wasn't seeing any data for it. That's until I realized, it was sending data under the host $COMPUTERNAME. I ran "splunk show servername" and it shows the right host name.

0 Karma
1 Solution

tmontney
Builder

By not specifying a host value, Splunk UF will automatically send the correct hostname.

View solution in original post

0 Karma

tmontney
Builder

By not specifying a host value, Splunk UF will automatically send the correct hostname.

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

When Splunk starts up for the first time, it writes a new inputs.conf in the $SPLUNK_HOME/etc/system/local subdirectory. This inputs.conf contains just a [default] section like you've described above, with the host set to the "discovered" name of the system. If you are looking to create a system image:

http://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Integrateauniversalforwarderontoasystemimage

tmontney
Builder

I'm not actually trying to create a system image (although I might in the future). I simply created an app on the Splunk server, and deployed it to existing clients. Clients are only referencing the app, not the /etc/system/local conf (that's my intention anyway). Since this is going out automatically, the hostname needs to be a variable. This worked for all laptops except one (my own).

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...