How is it possible to use the host value and not ip address or the dns name for a tcp input?
Answer Posted / Preeti Chaudhry
To configure Splunk to accept data using the host value instead of IP address or DNS name, you can set the 'local-ip' directive in your inputs.conf file to match the hostname as it appears in the TCP event header. This allows Splunk to properly identify and index incoming events.
| Is This Answer Correct ? | 0 Yes | 0 No |
Post New Answer View All Answers