Hi, splunkers:
At few days ago I've been asked that which network interface is splunk using for forwarder send data to indexer?
The scenario is my customer told me that their splunk is sending data via the produce env. IP just like 10.216.3.9, but splunk should use IP 10.216.2.10 for that will be more safe and they can manage them with more convenience.
Any idea for this? Thx!
@aojie654,
By default, Splunk will bind to all available IP addresses. You can bind splunkd process to specific IP by configuring SPLUNK_BINDIP
in $SPLUNK_HOME/etc/splunk-launch.conf
.
Reference : Bind Splunk to an IP
@aojie654,
By default, Splunk will bind to all available IP addresses. You can bind splunkd process to specific IP by configuring SPLUNK_BINDIP
in $SPLUNK_HOME/etc/splunk-launch.conf
.
Reference : Bind Splunk to an IP
Hi, renjith.nair:
It looks like I'd changed my management ip in configure files in web.conf
and splunk-launch.conf
When I restarted the splunk, the following message showed in terminal:
The Splunk web interface is at http://192.168.3.191:8000
But if I goto forwarder management page, it showed like this:
Host Name Client Name Instance Name IP Address Actions Machine Type Deployed Apps Phone Home
aj-splunk-fd 0D7AEC97-217F-47AB-AB43-EC60C2D26A14 aj-splunk-fd 192.168.3.190 Delete Record linux-x86_64 4 deployed a few seconds ago
That's looks no use for this?