<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710048#M29136</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Yes I did these commands many times it connects. It was puzzling the Splunk guys and I didn't find anything in the logs and&amp;nbsp; I sent the Splunk-Diag to the Splunk engineers and they found nothing. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think we need a Red Hat expert who can look at the CIS hardening controls and state its that one.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk Leadership should definitely step in and find a solution if this is a bug with CIS Red Hat 9 &lt;STRONG&gt;" v2 "&lt;/STRONG&gt; level 1, with there Splunk product 9.3 and 9.4 application.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2025 23:00:58 GMT</pubDate>
    <dc:creator>jwestbank</dc:creator>
    <dc:date>2025-01-28T23:00:58Z</dc:date>
    <item>
      <title>Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/709986#M29124</link>
      <description>&lt;P&gt;Hey Splunk Community,&lt;/P&gt;&lt;P&gt;I was wondering if anyone has figured out what is the cause for the GUI not to work at all in a new install of Splunk 9.3 or 9.4 on a [CIS Red Hat ver. 9 Level 1] image. I have been trying to manage the the Splunk server with the GUI and it just wont come up. I can SSH all day long, but no GUI. I did come to the conclusion that its only on the [CIS Red Hat 9 level 1] image and not on an original RHEL Red Hat 9 image. This issues does not appear on [CIS Red Hat 8 level 1] image.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone has the fix action to what CIS control configuration is causing this it would be greatly appreciated. I am positive if anyone in the &lt;STRONG&gt;[Gov. sector]&lt;/STRONG&gt; is going to be hardening there server with CIS RHEL 9 control images they are going to run across this problem.&lt;/P&gt;&lt;P&gt;Thanks - Johnny&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 15:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/709986#M29124</guid>
      <dc:creator>jwestbank</dc:creator>
      <dc:date>2025-01-28T15:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/709988#M29125</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255654"&gt;@jwestbank&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;a very stupid question: did you disabled iptables or firewalld on the port 8000?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 15:58:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/709988#M29125</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-28T15:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/709991#M29126</link>
      <description>&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;gcusello&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;Firewalld is enabled and I have all the respective ports enabled as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;firewall-cmd --zone=public --permanent --add-port 8000/tcp&lt;BR /&gt;firewall-cmd --reload&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;I have worked with Splunk Support and Red Hat Support and they have verified my configuration and still didn't figure it out. So the only thing it could be is a hardening configuration from CIS level 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;SPAN&gt;Thank you buddy for your polite comments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 16:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/709991#M29126</guid>
      <dc:creator>jwestbank</dc:creator>
      <dc:date>2025-01-28T16:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710032#M29132</link>
      <description>&lt;P&gt;Has splunk started web gui process and are it listening on that host or is it totally down?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 19:48:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710032#M29132</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-28T19:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710036#M29133</link>
      <description>&lt;P&gt;Web.conf file configuration&lt;/P&gt;&lt;P&gt;[settings]&lt;BR /&gt;enableSplunkWebSSL = true&lt;BR /&gt;httpport = 8000&lt;/P&gt;&lt;P&gt;##############################&lt;/P&gt;&lt;P&gt;root@SplunkPROD bin]# ./splunk enable web-ssl&lt;BR /&gt;WARNING: Server Certificate Hostname Validation is disabled. Please see server.conf/[sslConfig]/cliVerifyServerName for details.&lt;BR /&gt;Your session is invalid. Please login.&lt;BR /&gt;Splunk username: jwestbank&lt;BR /&gt;Password:&lt;BR /&gt;You need to restart the Splunk Server (splunkd) for your changes to take effect.&lt;BR /&gt;[root@SplunkPROD bin]# ./splunk restart&lt;BR /&gt;Stopping splunkd...&lt;BR /&gt;Shutting down. Please wait, as this may take a few minutes.&lt;BR /&gt;... [ OK ]&lt;BR /&gt;Stopping splunk helpers...&lt;BR /&gt;[ OK ]&lt;BR /&gt;Done.&lt;/P&gt;&lt;P&gt;Splunk&amp;gt; Now with more code!&lt;/P&gt;&lt;P&gt;Checking prerequisites...&lt;BR /&gt;Checking http port [8000]: open&lt;BR /&gt;Checking mgmt port [8089]: open&lt;BR /&gt;Checking appserver port [127.0.0.1:8065]: open&lt;BR /&gt;Checking kvstore port [8191]: open&lt;BR /&gt;Checking configuration... Done.&lt;BR /&gt;Checking critical directories... Done&lt;BR /&gt;Checking indexes...&lt;BR /&gt;Validated: _audit _configtracker _dsappevent _dsclient _dsphonehome _internal _introspection _metrics _metrics_rollup _telemetry _thefishbucket history main summary&lt;BR /&gt;Done&lt;BR /&gt;Checking filesystem compatibility... Done&lt;BR /&gt;Checking conf files for problems...&lt;/P&gt;&lt;P&gt;Done&lt;BR /&gt;Checking default conf files for edits...&lt;BR /&gt;Validating installed files against hashes from '/opt/splunk/splunk-9.3.0-51ccf43db5bd-linux-2.6-x86_64-manifest'&lt;BR /&gt;All installed files intact.&lt;BR /&gt;Done&lt;BR /&gt;All preliminary checks passed.&lt;/P&gt;&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;BR /&gt;PYTHONHTTPSVERIFY is set to 0 in splunk-launch.conf disabling certificate validation for the httplib and urllib libraries shipped with the embedded Python interpreter; must be set to "1" for increased security&lt;BR /&gt;Done&lt;BR /&gt;[ OK ]&lt;/P&gt;&lt;P&gt;Waiting for web server at &lt;A href="https://127.0.0.1:8000" target="_blank"&gt;https://127.0.0.1:8000&lt;/A&gt; to be available............WARNING: Server Certificate Hostname Validation is disabled. Please see server.conf/[sslConfig]/cliVerifyServerName for details.&lt;BR /&gt;. Done&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you get stuck, we're here to help.&lt;BR /&gt;Look for answers here: &lt;A href="http://docs.splunk.com" target="_blank"&gt;http://docs.splunk.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The Splunk web interface is at &lt;A href="https://SplunkPROD:8000" target="_blank"&gt;https://SplunkPROD:8000&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710036#M29133</guid>
      <dc:creator>jwestbank</dc:creator>
      <dc:date>2025-01-28T21:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710037#M29134</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;root@SplunkPROD bin]# ss -tunlp | grep 8000&lt;BR /&gt;&lt;STRONG&gt;tcp LISTEN 0 128 0.0.0.0:8000 0.0.0.0:* users:(("splunkd",pid=17948,fd=179))&lt;/STRONG&gt;&lt;BR /&gt;[root@SplunPROD bin]#&lt;/P&gt;&lt;P&gt;root@SplunkPROD bin]# firewall-cmd --list-ports&lt;BR /&gt;&lt;STRONG&gt;443/tcp 8000/tcp 8089/tcp 8191/tcp 9997/tcp 8000/udp 9997/udp&lt;/STRONG&gt;&lt;BR /&gt;[root@SplunkPROD bin]#&lt;/P&gt;&lt;P&gt;root@SplunkPROD bin]# firewall-cmd --list-all&lt;BR /&gt;public (active)&lt;BR /&gt;target: default&lt;BR /&gt;icmp-block-inversion: no&lt;BR /&gt;interfaces: &lt;STRONG&gt;eth0&lt;/STRONG&gt;&lt;BR /&gt;sources:&lt;BR /&gt;services: cockpit dhcpv6-client ssh&lt;BR /&gt;&lt;STRONG&gt;ports: 8000/tcp 8000/udp 8089/tcp 8191/tcp 443/tcp 9997/tcp 9997/udp&lt;/STRONG&gt;&lt;BR /&gt;protocols:&lt;BR /&gt;forward: yes&lt;BR /&gt;masquerade: no&lt;BR /&gt;forward-ports:&lt;BR /&gt;source-ports:&lt;BR /&gt;icmp-blocks:&lt;BR /&gt;rich rules:&lt;BR /&gt;[root@SplunkPROD bin]#&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710037#M29134</guid>
      <dc:creator>jwestbank</dc:creator>
      <dc:date>2025-01-28T21:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710039#M29135</link>
      <description>&lt;P&gt;Based on that, it’s up and running.&lt;/P&gt;&lt;P&gt;Have you try it with that node e.g. with curl and using localhost?&lt;/P&gt;&lt;P&gt;How about splunkd_acces.log and web logs etc? Are there anything?&lt;/P&gt;&lt;P&gt;And selinux? Any entries on auditd?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:48:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710039#M29135</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-28T21:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710048#M29136</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yes I did these commands many times it connects. It was puzzling the Splunk guys and I didn't find anything in the logs and&amp;nbsp; I sent the Splunk-Diag to the Splunk engineers and they found nothing. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think we need a Red Hat expert who can look at the CIS hardening controls and state its that one.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk Leadership should definitely step in and find a solution if this is a bug with CIS Red Hat 9 &lt;STRONG&gt;" v2 "&lt;/STRONG&gt; level 1, with there Splunk product 9.3 and 9.4 application.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 23:00:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710048#M29136</guid>
      <dc:creator>jwestbank</dc:creator>
      <dc:date>2025-01-28T23:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710080#M29138</link>
      <description>&lt;P&gt;If you can connect locally with curl everything is basically ok. It means that issue is on network side. Have you any node on the same subnet (no network fw between it and splunk), where you could try curl to this host?&lt;/P&gt;&lt;P&gt;Another test which needs to do is try curl on splunk host, but use the official url not localhost. And if there are LB/VIP address before splunk nodes, then use also that and splunk nodes ip too.&lt;/P&gt;&lt;P&gt;In that way we can try to find where the blocking fw.&lt;/P&gt;&lt;P&gt;We have several RHEL 9 cis v1 hardened boxes and there is no issues with them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 05:18:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/710080#M29138</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-29T05:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/743339#M29328</link>
      <description>&lt;P&gt;unnecessary comment.&amp;nbsp; expect better from a Trust member&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 22:34:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/743339#M29328</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2025-04-02T22:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/743341#M29329</link>
      <description>Do you want to explain what you are meaning?</description>
      <pubDate>Wed, 02 Apr 2025 22:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/743341#M29329</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-04-02T22:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 9.3+ Deployment on CIS Red Hat 9 level 1 image - No GUI</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/746471#M29440</link>
      <description>&lt;P&gt;I'm assuming they thought the "very stupid question" part was directed at the OP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2025 14:19:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-9-3-Deployment-on-CIS-Red-Hat-9-level-1-image-No-GUI/m-p/746471#M29440</guid>
      <dc:creator>R15</dc:creator>
      <dc:date>2025-05-19T14:19:51Z</dc:date>
    </item>
  </channel>
</rss>

