<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk instances will not connect to HTTP port in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320395#M8295</link>
    <description>&lt;P&gt;&lt;STRONG&gt;web.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[settings]&lt;BR /&gt;
httpport = 443&lt;BR /&gt;
enableSplunkWebSSL = true&lt;BR /&gt;
privKeyPath = &lt;BR /&gt;
serverCert = &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;server.conf:&lt;/STRONG&gt;&lt;BR /&gt;
[general]&lt;BR /&gt;
serverName = .domain.com&lt;/P&gt;

&lt;P&gt;[sslConfig]&lt;BR /&gt;
sslPassword = &lt;/P&gt;</description>
    <pubDate>Thu, 06 Apr 2017 19:50:50 GMT</pubDate>
    <dc:creator>jonesnadiam</dc:creator>
    <dc:date>2017-04-06T19:50:50Z</dc:date>
    <item>
      <title>Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320389#M8289</link>
      <description>&lt;P&gt;After installing SSL certificates and changing the default Splunk web port to 443, I receive the following error:&lt;/P&gt;

&lt;P&gt;Checking http port [443]: already bound&lt;BR /&gt;
ERROR: The http port [443] is already bound.  Splunk needs to use this port.&lt;/P&gt;

&lt;P&gt;After killing the processes associated with this port and rebooting, I am still unable to start Splunk, receiving the same error.  I've also tried the following with no luck:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Confirmed the loopback address in /etc/hosts and ifconfig lo&lt;/LI&gt;
&lt;LI&gt;Confirmed there was no BIND_IP defined in /opt/splunk/etc/splunk-launch.conf&lt;/LI&gt;
&lt;LI&gt;Tried removing/re-installing Splunk&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any other suggestions?&lt;/P&gt;

&lt;P&gt;Note -  I have 5 instances of Splunk (1DS, 2SH, 2HF).  The only instance that was able to successfully connect to the port was the DS.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 17:43:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320389#M8289</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2017-04-06T17:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320390#M8290</link>
      <description>&lt;P&gt;Is the host windows or linux?  From the host try 'telnet localhost 443' to see if that port is in use.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 17:52:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320390#M8290</guid>
      <dc:creator>suarezry</dc:creator>
      <dc:date>2017-04-06T17:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320391#M8291</link>
      <description>&lt;P&gt;This is a Linux server.  I receiving the following:&lt;/P&gt;

&lt;P&gt;Trying ::1...&lt;BR /&gt;
Trying 127.0.0.1...&lt;BR /&gt;
telnet: Unable to connect to remote host: Connection refused&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 18:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320391#M8291</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2017-04-06T18:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320392#M8292</link>
      <description>&lt;P&gt;Ok, so port 443 is free.  What user are you trying to run splunk as?  Port 443 is a privileged port.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 19:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320392#M8292</guid>
      <dc:creator>suarezry</dc:creator>
      <dc:date>2017-04-06T19:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320393#M8293</link>
      <description>&lt;P&gt;Yep - I am running as root &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 19:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320393#M8293</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2017-04-06T19:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320394#M8294</link>
      <description>&lt;P&gt;post your $SPLUNK_HOME/etc/system/local/web.conf and server.conf&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 19:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320394#M8294</guid>
      <dc:creator>suarezry</dc:creator>
      <dc:date>2017-04-06T19:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320395#M8295</link>
      <description>&lt;P&gt;&lt;STRONG&gt;web.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[settings]&lt;BR /&gt;
httpport = 443&lt;BR /&gt;
enableSplunkWebSSL = true&lt;BR /&gt;
privKeyPath = &lt;BR /&gt;
serverCert = &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;server.conf:&lt;/STRONG&gt;&lt;BR /&gt;
[general]&lt;BR /&gt;
serverName = .domain.com&lt;/P&gt;

&lt;P&gt;[sslConfig]&lt;BR /&gt;
sslPassword = &lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 19:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320395#M8295</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2017-04-06T19:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320396#M8296</link>
      <description>&lt;P&gt;Try changing the port to 8443 just to confirm it starts up fine and not a config issue.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 19:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320396#M8296</guid>
      <dc:creator>suarezry</dc:creator>
      <dc:date>2017-04-06T19:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320397#M8297</link>
      <description>&lt;P&gt;Yep, that works fine:&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
Checking http port [8443]: open&lt;BR /&gt;
Checking mgmt port [8089]: open&lt;BR /&gt;
Checking appserver port [127.0.0.1:8065]: open&lt;BR /&gt;
Checking kvstore port [8191]: open&lt;BR /&gt;
Checking configuration... Done.&lt;BR /&gt;
Checking critical directories... Done&lt;BR /&gt;
Checking indexes...&lt;BR /&gt;
[...]&lt;BR /&gt;
All preliminary checks passed.&lt;/P&gt;

&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;BR /&gt;
Done&lt;/P&gt;

&lt;P&gt;Waiting for web server at &lt;A href="https://127.0.0.1:8443"&gt;https://127.0.0.1:8443&lt;/A&gt; to be available..........&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 20:05:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320397#M8297</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2017-04-06T20:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320398#M8298</link>
      <description>&lt;P&gt;What is the output of these 2 commands:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;netstat -na|grep 443
lsof -i|grep 443
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Apr 2017 20:17:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320398#M8298</guid>
      <dc:creator>suarezry</dc:creator>
      <dc:date>2017-04-06T20:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320399#M8299</link>
      <description>&lt;P&gt;When running the netstat command, I get the following:&lt;BR /&gt;
tcp        0      1  :55742   :443       SYN_SENT&lt;/P&gt;

&lt;P&gt;When running the lsof command, I get the following:&lt;BR /&gt;
COMMAND    PID USER   FD   TYPE DEVICE SIZE/OFF NODE NAME&lt;BR /&gt;
connector 3899 root    6u  IPv4  92461      0t0  TCP servername.domain.com:58607-&amp;gt;name.domain.com:https (SYN_SENT)&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 01:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320399#M8299</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2017-04-07T01:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320400#M8300</link>
      <description>&lt;P&gt;Wow ok...So you confirmed nothing is bound to port 443,  your loopback and splunk-launch.conf is good, and you are starting splunk as root and it starts fine with an alternate port.&lt;/P&gt;

&lt;P&gt;Sorry, I don't know what else would cause this issue.  Time to engage support?  Let us know the cause if you find out!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2017 13:49:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320400#M8300</guid>
      <dc:creator>suarezry</dc:creator>
      <dc:date>2017-04-07T13:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320401#M8301</link>
      <description>&lt;P&gt;FYI - &lt;/P&gt;

&lt;P&gt;We needed to update &lt;STRONG&gt;SPLUNK_OS_USER=splunk&lt;/STRONG&gt; to &lt;STRONG&gt;SPLUNK_OS_USER=root&lt;/STRONG&gt; in &lt;STRONG&gt;$SPLUNK_HOME/etc/splunk-launch.conf&lt;/STRONG&gt;.&lt;/P&gt;

&lt;P&gt;Spunk was installed and running as root but needed to be started as root.  The ownership of the $SPLUNK_HOME directory also needed to be changed to root (instead of splunk).  Changing the line above solved the problem.&lt;/P&gt;

&lt;P&gt;Thanks so much for the help suarezry! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:37:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320401#M8301</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2020-09-29T13:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320402#M8302</link>
      <description>&lt;P&gt;Answered above - thanks again for the help!&lt;/P&gt;</description>
      <pubDate>Sun, 09 Apr 2017 22:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320402#M8302</guid>
      <dc:creator>jonesnadiam</dc:creator>
      <dc:date>2017-04-09T22:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320403#M8303</link>
      <description>&lt;P&gt;in case of non-root user, what should be the option?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2017 05:47:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320403#M8303</guid>
      <dc:creator>anand_singh17</dc:creator>
      <dc:date>2017-08-13T05:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320404#M8304</link>
      <description>&lt;P&gt;you need to check you bucket status. check your splunkd.log.&lt;/P&gt;

&lt;P&gt;you will get the actual reason for it.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2017 05:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/320404#M8304</guid>
      <dc:creator>anand_singh17</dc:creator>
      <dc:date>2017-08-13T05:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/578176#M15752</link>
      <description>&lt;P&gt;More secure way:&lt;BR /&gt;&lt;EM&gt;sudo setcap 'cap_net_bind_service=+ep' /opt/splunk/bin/splunkd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;echo /opt/splunk/lib | sudo tee /etc/ld.so.conf.d/splunk.conf&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sudo ldconfig&lt;/EM&gt;&lt;BR /&gt;Then you can run Splunk as non-root user on port 443.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 09:39:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/578176#M15752</guid>
      <dc:creator>mpavlas</dc:creator>
      <dc:date>2021-12-13T09:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk instances will not connect to HTTP port</title>
      <link>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/578177#M15753</link>
      <description>&lt;P&gt;Sorry, you need&lt;EM&gt;&lt;BR /&gt;sudo setcap 'cap_net_bind_service=+ep' /opt/splunk/bin/splunk&lt;BR /&gt;&lt;/EM&gt;as well&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 10:00:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-instances-will-not-connect-to-HTTP-port/m-p/578177#M15753</guid>
      <dc:creator>mpavlas</dc:creator>
      <dc:date>2021-12-13T10:00:07Z</dc:date>
    </item>
  </channel>
</rss>

