All Apps and Add-ons

Can't access Splunk web console

jmspbooth
New Member

So I have Splunk Community deployed on a micro instance of CentOS 7 on google cloud platform.

  • GDP Firewall has 8000 open to all instances from everywhere.
  • CentOS machine has 8000 TCP and UDP open on firewall-cmd.
  • Splunk is running with a non-root user
  • Opened connections from http and https
  • Tried changing the port to 7000 and making the other changes and it is still not available.
  • Tried using multiple browsers will no effect.
  • Confirmed that splunk is running and listening on port 8000

Working with GCP helpdesk as well since the DNS entry isn't working either so I am using the external IP directly. Its been about 24 hours so any latency between networking updates should have happened by now.

0 Karma

jmsbooth
New Member

Here are the configs requested.

firewall-cmd
trusted (active)
target: ACCEPT
icmp-block-inversion: no
interfaces: eth0
sources:
services:
ports: 8000/tcp 8000/udp
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:

Google Cloud
splunk-allow
Network
default
Priority
1000
Direction
Ingress
Action on match
Allow
Targets
Target tags
splunk
Source filters
IP ranges
0.0.0.0
Protocols and ports
tcp:8000
udp:8000
tcp:8191
udp:8191
tcp:8089
udp:8089
Enforcement
Enabled

0 Karma

highsplunker
Contributor

i too could not access my splunk wer from home browser, but my problem was precisely in GCP firewall rules: be careful with you filters (labes, masks, etc.) - there is not difficulty there, actually. have a nice day.

0 Karma

koshyk
Super Champion

can u paste the settings of
- firewall-cmd list output
- Firewall settings for GCP for the open port 8000

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...