<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error message on Splunk in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-message-on-Splunk/m-p/758481#M23897</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315736"&gt;@hordoffa1970&lt;/a&gt;&amp;nbsp;The error message&amp;nbsp;&lt;EM&gt;“Failed to create. Configuration for port 9997 already exists”&lt;/EM&gt;&amp;nbsp;means the receiving port you’re trying to configure is already set up somewhere in your Splunk configuration. Port 9997 is the default receiving port for Splunk indexers, so if it’s already enabled, trying to add it again will trigger this message.&lt;/P&gt;&lt;PRE&gt;You can check existing receiving configuration In Splunk Web by navigating to:&amp;nbsp;&lt;BR /&gt;&lt;FONT color="#000000"&gt;Settings → Forwarding and Receiving → Configure Receiving&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;You should see port 9997 already listed. If 9997 is already active, you don’t need to add it again. Just confirm it’s listening.&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;EM&gt; Giving Karma &amp;amp;&amp;nbsp;Marking the answer helps others find solutions faster!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;!--  EndFragment   --&gt;&lt;/P&gt;&lt;OL&gt;&lt;UL&gt;&lt;!--  EndFragment   --&gt;&lt;/UL&gt;&lt;/OL&gt;&lt;P&gt;&lt;!--  EndFragment   --&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Feb 2026 02:32:47 GMT</pubDate>
    <dc:creator>kknairr</dc:creator>
    <dc:date>2026-02-19T02:32:47Z</dc:date>
    <item>
      <title>Error message on Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-message-on-Splunk/m-p/758446#M23891</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Encountered the following error while trying to save: Failed to create. Configuration for port 9997 already exists. I am getting this message on Splunk when I try to configure and save the listening port&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 03:04:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-message-on-Splunk/m-p/758446#M23891</guid>
      <dc:creator>hordoffa1970</dc:creator>
      <dc:date>2026-02-18T03:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Error message on Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-message-on-Splunk/m-p/758456#M23894</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315736"&gt;@hordoffa1970&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the error suggests, it looks like something is already listening on port 9997.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What exactly is it you are trying to do? Do you already have an inputs.conf configured to receive data (or is something else on your system using port 9997)?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 11:30:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-message-on-Splunk/m-p/758456#M23894</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-02-18T11:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Error message on Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Error-message-on-Splunk/m-p/758481#M23897</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/315736"&gt;@hordoffa1970&lt;/a&gt;&amp;nbsp;The error message&amp;nbsp;&lt;EM&gt;“Failed to create. Configuration for port 9997 already exists”&lt;/EM&gt;&amp;nbsp;means the receiving port you’re trying to configure is already set up somewhere in your Splunk configuration. Port 9997 is the default receiving port for Splunk indexers, so if it’s already enabled, trying to add it again will trigger this message.&lt;/P&gt;&lt;PRE&gt;You can check existing receiving configuration In Splunk Web by navigating to:&amp;nbsp;&lt;BR /&gt;&lt;FONT color="#000000"&gt;Settings → Forwarding and Receiving → Configure Receiving&lt;/FONT&gt;&lt;/PRE&gt;&lt;P&gt;You should see port 9997 already listed. If 9997 is already active, you don’t need to add it again. Just confirm it’s listening.&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;EM&gt; Giving Karma &amp;amp;&amp;nbsp;Marking the answer helps others find solutions faster!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;!--  EndFragment   --&gt;&lt;/P&gt;&lt;OL&gt;&lt;UL&gt;&lt;!--  EndFragment   --&gt;&lt;/UL&gt;&lt;/OL&gt;&lt;P&gt;&lt;!--  EndFragment   --&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 02:32:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Error-message-on-Splunk/m-p/758481#M23897</guid>
      <dc:creator>kknairr</dc:creator>
      <dc:date>2026-02-19T02:32:47Z</dc:date>
    </item>
  </channel>
</rss>

