<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is HTTP Event Collector listening only on 127.0.0.1 (localhost) address? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283415#M54180</link>
    <description>&lt;P&gt;I enabled the HTTP Event Collector and I can see on my Centos 7 by running the ss -an command that it is listening only on 127.0.0.1 address. As a result the curl is working when calling 127.0.0.1:8088 and connection is refused when calling :8088 from the local ssh terminal&lt;/P&gt;

&lt;P&gt;Any idea how to fix this issue?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2016 18:17:03 GMT</pubDate>
    <dc:creator>rvencu</dc:creator>
    <dc:date>2016-10-27T18:17:03Z</dc:date>
    <item>
      <title>Why is HTTP Event Collector listening only on 127.0.0.1 (localhost) address?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283415#M54180</link>
      <description>&lt;P&gt;I enabled the HTTP Event Collector and I can see on my Centos 7 by running the ss -an command that it is listening only on 127.0.0.1 address. As a result the curl is working when calling 127.0.0.1:8088 and connection is refused when calling :8088 from the local ssh terminal&lt;/P&gt;

&lt;P&gt;Any idea how to fix this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 18:17:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283415#M54180</guid>
      <dc:creator>rvencu</dc:creator>
      <dc:date>2016-10-27T18:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why is HTTP Event Collector listening only on 127.0.0.1 (localhost) address?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283416#M54181</link>
      <description>&lt;P&gt;[root@splunk ~]# firewall-cmd --list-all&lt;BR /&gt;
public (default, active)&lt;BR /&gt;
  interfaces: eth0&lt;BR /&gt;
  sources:&lt;BR /&gt;
  services: dhcpv6-client ssh&lt;BR /&gt;
  ports: 443/tcp 80/tcp 2222/tcp 4443/tcp 8886/tcp 8088/tcp&lt;BR /&gt;
  masquerade: no&lt;BR /&gt;
  forward-ports:&lt;BR /&gt;
  icmp-blocks:&lt;BR /&gt;
  rich rules:&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 18:17:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283416#M54181</guid>
      <dc:creator>rvencu</dc:creator>
      <dc:date>2016-10-27T18:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is HTTP Event Collector listening only on 127.0.0.1 (localhost) address?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283417#M54182</link>
      <description>&lt;P&gt;I solved it. My free splunk is deliberately set to be accessible only from localhost because user authentication can be done only through an NGINX reverse proxy. Hence the listening limitation.&lt;/P&gt;

&lt;P&gt;I added a second reverse proxy setting for the HTTP Event Collector and all is working fine now.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 20:06:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283417#M54182</guid>
      <dc:creator>rvencu</dc:creator>
      <dc:date>2016-10-27T20:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why is HTTP Event Collector listening only on 127.0.0.1 (localhost) address?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283418#M54183</link>
      <description>&lt;P&gt;I think I'm having a similar issue, we have an Apache2 reverse proxy in front of our Splunk instance, what type of setting did you configure to allow the HEC explicitly?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 22:40:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-HTTP-Event-Collector-listening-only-on-127-0-0-1/m-p/283418#M54183</guid>
      <dc:creator>Filmhooligan</dc:creator>
      <dc:date>2018-07-05T22:40:52Z</dc:date>
    </item>
  </channel>
</rss>

