Deployment Architecture

Run Splunk Universal forwarder 6.3.4 on linux with defaultPort disabled

andrei_radu
New Member

I have installed the Splunk Universal Forwarder version 6.3.4 on a RedHat 7.1 server and, after disabling the management port the splunkd process crashes. For disabling the default port we use an app with server.conf as follows:
disableDefaultPort = true

This configuration works fine with older versions of Splunk Universal forwarder like 6.1.6 or 6.2.5

Any suggestions?

Tags (1)
0 Karma
1 Solution

muebel
SplunkTrust
SplunkTrust

is that configuration directive within the [httpServer] stanza?

View solution in original post

muebel
SplunkTrust
SplunkTrust

is that configuration directive within the [httpServer] stanza?

andrei_radu
New Member

no, it's not with the [httpServer] stanza

0 Karma

andrei_radu
New Member

Worked with the [httpServer] stanza. Thanks a lot!

0 Karma

jkat54
SplunkTrust
SplunkTrust

I converted this to an answer. Please mark it as the correct one.

0 Karma

Jeremiah
Motivator

If its crashing, you should see a crash log in the var/log/splunk directory. Try stripping out any other changes you've made to the forwarder, and just try restarting with the management port disabled. Does it still crash? You might want to open a support ticket for this.

0 Karma

andrei_radu
New Member

Yes, there's a crash file in /var/log/splunk directory. Restarting splunk with the management port disabled makes it crash again and again.

0 Karma

aosso
Path Finder

Any reason to use 6.3.4? You may try the newer builds: 6.3.6 or 6.4.2 and see if it works.

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...