<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot access splunkweb after initial install in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Cannot-access-splunkweb-after-initial-install/m-p/32758#M901</link>
    <description>&lt;P&gt;Like I said, d'oh!&lt;/P&gt;

&lt;P&gt;Yes, that was the problem.  I am afraid I looked at everything but the most obvious.&lt;/P&gt;

&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Dec 2011 04:24:49 GMT</pubDate>
    <dc:creator>bnklein</dc:creator>
    <dc:date>2011-12-10T04:24:49Z</dc:date>
    <item>
      <title>Cannot access splunkweb after initial install</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Cannot-access-splunkweb-after-initial-install/m-p/32756#M899</link>
      <description>&lt;P&gt;I am new to Splunk and just installed splunk-4.2.4-110225-linux-2.6-x86_64.rpm on Red Hat Linux Enterprise 6.  The installation went fine with no noted errors.  &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;However I am unable to to connect to splunkweb.&lt;/STRONG&gt;  &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;I am running under a trial license. &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I have changed the default admin password.  &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;As per the "What's Splunk Web" page, I have added &lt;BR /&gt;
[general]&lt;BR /&gt;
allowRemoteLogin = always&lt;BR /&gt;
to $SPLUNK_HOME/etc/local/server.conf (which did not exist) as well as&lt;BR /&gt;
$SPLUNK_HOME/etc/system/local/server.conf  (which did exist)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I have confirmed the splunkweb python task is running.&lt;BR /&gt;&lt;BR /&gt;
'splunk show web-port' shows Web-port: 8000&lt;BR /&gt;
lsof -i tcp:8000 shows irdmi running on tcp/8000.  (Red Hat's /etc/services used for displaying network services shows irdmi running on tcp/8000).  &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Just to make certain there was no conflict I changed splunkweb's port to 8080 and restarted splunk.  A subsequent show web-port and lsof confirm python is listening on tcp/8080 even though I cannot connect to it.  (It's not a network connectivity issue; I can ping the server from the client, and the client from the server).&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;splunkd_access.log shows for each access:&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;127.0.0.1 - splunk-system-user [09/Dec/2011:19:05:29.674 -0600] "POST /servicesNS/nobody/search/saved/searches/Top%20five%20sourcetypes/notify?trigger.condition_state=1 HTTP/1.0" 200 2089 - - - 9ms&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The web_service.log does not show any errors.&lt;/LI&gt;
&lt;LI&gt;&lt;/LI&gt;
&lt;LI&gt;I have confirmed that all files are owned by splunk and there are no errors when I restart.  I have tried running under the splunk logonid as well as root (only for testing)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Any ideas?  I'm certain it's one of those late Friday night d'oh's.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;bk&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:12:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Cannot-access-splunkweb-after-initial-install/m-p/32756#M899</guid>
      <dc:creator>bnklein</dc:creator>
      <dc:date>2020-09-28T10:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access splunkweb after initial install</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Cannot-access-splunkweb-after-initial-install/m-p/32757#M900</link>
      <description>&lt;P&gt;Did you either disable the RHEL iptables firewall, or add the Splunkweb ports to the firewall's allow list?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2011 02:31:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Cannot-access-splunkweb-after-initial-install/m-p/32757#M900</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-12-10T02:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access splunkweb after initial install</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Cannot-access-splunkweb-after-initial-install/m-p/32758#M901</link>
      <description>&lt;P&gt;Like I said, d'oh!&lt;/P&gt;

&lt;P&gt;Yes, that was the problem.  I am afraid I looked at everything but the most obvious.&lt;/P&gt;

&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2011 04:24:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Cannot-access-splunkweb-after-initial-install/m-p/32758#M901</guid>
      <dc:creator>bnklein</dc:creator>
      <dc:date>2011-12-10T04:24:49Z</dc:date>
    </item>
  </channel>
</rss>

