Splunk Search

Splunk is not working. localhost refused to connect.

clgzcom
New Member

This site can’t be reached
localhost refused to connect.
Did you mean http://localhost8000.com/?
Search Google for localhost 8000
ERR_CONNECTION_REFUSED

--
OS: Windows Server 2016

alt text

0 Karma

MikeBertelsen
Communicator

I assume by now you figured out that the webserver is not enabled.
If it is still an issue do the following:
cd c:\program files\splunk\bin
splunk stop
splunk enable webserver
splunk start

When Splunk starts up you will see that there are two ports being opened instead of one; the mgmt port 8089 and the http port 8000

Sndiman
New Member

If I'm told 'access is denied' what then ?

0 Karma

akothapa
Engager

perfect answer. Thanks a lot!!!!

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Is it a local system installation ?
Do you have ssl enabled for web ? then try https
Is firewall enabled which blocks 8000 ?

Happy Splunking!
0 Karma

clgzcom
New Member

Yes it is local system installation.
Yes, I tried but it doesn't work.

I also checked if there are connections with the port 800 by running netstat -an | select-string 8000 and there aren't

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

If the netstat is not showing 8000, then splunk is also not listening to that. Is Splunk running and have you changed the port ?

Happy Splunking!
0 Karma

clgzcom
New Member

No, everything is default

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Ok can you restart and what's the last message in the console about splunkweb start? Also look at the splunkd.log to see if there are any errors reported

Happy Splunking!
0 Karma

clgzcom
New Member

I checked the splunkd.log snd there is no reference to "splunkweb start"

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

Still feels that the port is not listening or blocked. Restart splunk from the command line, recheck the port the web is connecting to - 8000,8001,8002. Also check the web_service log

Happy Splunking!
0 Karma

clgzcom
New Member

I did checked with the windows firewall turned off.

0 Karma

bharath_Splunk
New Member

Follow These steps:

Open cmd as Administrator

C:\Windows\system32> cd 
C:\Windows\system32> cd C:\Program Files\Splunk\bin   

C:\Program Files\Splunk\bin>splunk start

Splunk> Be an IT superhero. Go home early.

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
(skipping validation of index paths because not running as LocalSystem)
Validated: _audit _internal _introspection _metrics _metrics_rollup _telemetry _thefishbucket history main summary
Done
Checking filesystem compatibility... Done
Checking conf files for problems...
Done
Checking default conf files for edits...
Validating installed files against hashes from 'C:\Program Files\Splunk\splunk-8.0.4.1-ab7a85abaa98-windows-64-manifest'
All installed files intact.
Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...

Splunkd: Starting (pid 1116)
Done

Waiting for web server at http://******:8000 to be available... Done


If you get stuck, we're here to help.
Look for answers here: http://docs.splunk.com

The Splunk web interface is at http://*******:8000

now open browser and now it will work 

 

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...