<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Universal forwarder management port is closed in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676442#M18569</link>
    <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I updated Splunk Universal forwarder from 8.2.6 to 9.1.3 on a Debian host. No specific configuration basically, everything by default. I would like to use the REST capabilities which I already used with the older version but this time the port is not listening, however startup says its listening.&lt;BR /&gt;&lt;STRONG&gt;Checking mgmt port [8089]: open&lt;/STRONG&gt;&lt;BR /&gt;Netstat shows no 8089 as well.&lt;BR /&gt;Host has no firewall, no bulls**t, just pure playground and as I said older version worked perfectly.&lt;BR /&gt;What can be the problem, another bug in the software?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Feb 2024 22:07:20 GMT</pubDate>
    <dc:creator>eduardo1989</dc:creator>
    <dc:date>2024-02-02T22:07:20Z</dc:date>
    <item>
      <title>Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676442#M18569</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;I updated Splunk Universal forwarder from 8.2.6 to 9.1.3 on a Debian host. No specific configuration basically, everything by default. I would like to use the REST capabilities which I already used with the older version but this time the port is not listening, however startup says its listening.&lt;BR /&gt;&lt;STRONG&gt;Checking mgmt port [8089]: open&lt;/STRONG&gt;&lt;BR /&gt;Netstat shows no 8089 as well.&lt;BR /&gt;Host has no firewall, no bulls**t, just pure playground and as I said older version worked perfectly.&lt;BR /&gt;What can be the problem, another bug in the software?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 22:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676442#M18569</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2024-02-02T22:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676450#M18570</link>
      <description>&lt;P&gt;The report at startup indicates port 8089 is not in use by any process (it's "open" for use).&amp;nbsp; It does not mean Splunk is listening on that port (at least not yet).&lt;/P&gt;&lt;P&gt;Version 9.0 changed the default behavior of the UF's management port.&amp;nbsp; See the Release Notes at &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.8/ReleaseNotes/MeetSplunk#What.27s_New_in_9.0" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.8/ReleaseNotes/MeetSplunk#What.27s_New_in_9.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.8/ReleaseNotes/MeetSplunk#What.27s_New_in_9.0" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.8/ReleaseNotes/MeetSplunk#What.27s_New_in_9.0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 13:40:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676450#M18570</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-03T13:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676451#M18571</link>
      <description>&lt;P&gt;The thing is it does not listen at all on Linux after the mentioned version. On windows I could check and it works as defined. As it is written by default it is limited to localhost.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways thanks for this info.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 02:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676451#M18571</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2024-02-03T02:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676471#M18574</link>
      <description>&lt;P&gt;What you described is the new default behavior.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 13:41:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676471#M18574</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-03T13:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676472#M18575</link>
      <description>&lt;P&gt;Yes, in the meantime it turned out the default way it to listen on a UNIX Domain Socket and I need to switch with config back to the tcp method. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 14:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/676472#M18575</guid>
      <dc:creator>edmondpalcsarbi</dc:creator>
      <dc:date>2024-02-03T14:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/685016#M19193</link>
      <description>&lt;P&gt;I am having the same issue. I have also checked the Release Notes you linked. I already have those items configured:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$ bin/splunk btool web list | grep mgmtHostPort&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;mgmtHostPort = 0.0.0.0:8089&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$ bin/splunk btool server list | grep disableDefaultPort&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;disableDefaultPort = false&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But still, I don't see splunkd listening on port 8089:&lt;BR /&gt;$ sudo lsof -i tcp -P | grep 8089&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(I get nothing.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Universal Forwarder is v9.2.1 on Red Hat Enterprise Linux 8.9.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2024 18:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/685016#M19193</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2024-04-22T18:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/703293#M20643</link>
      <description>&lt;P&gt;What do you mean by&amp;nbsp;&lt;SPAN&gt;need to switch with config back to the tcp method?&lt;BR /&gt;How did you do that?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;after this change do you see it listen to port 8089?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;netstat -pant | egrep 8089&amp;nbsp; - do you see listen ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 23:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/703293#M20643</guid>
      <dc:creator>patelmc19</dc:creator>
      <dc:date>2024-10-31T23:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal forwarder management port is closed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/703348#M20657</link>
      <description>&lt;P&gt;This is what I have in "server.conf", in addition to what I have in "web.conf":&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[httpServer]
disableDefaultPort = false
mgmtMode = tcp&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;After that, splunkd starts to listen to TCP port 8089.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 20:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Universal-forwarder-management-port-is-closed/m-p/703348#M20657</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2024-11-01T20:50:17Z</dc:date>
    </item>
  </channel>
</rss>

