Deployment Architecture

Splunkweb Installation

antg334
Explorer

What are the steps needed to install Splunkweb on a Linux server?

Tags (2)
0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi antg334,

download your favorite source format like rpm, deb or tgz and install or unpack it on your server. Find all information needed in the docs about installation.

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi antg334,

download your favorite source format like rpm, deb or tgz and install or unpack it on your server. Find all information needed in the docs about installation.

cheers, MuS

MuS
SplunkTrust
SplunkTrust

Please mark this question as answered - thx

0 Karma

MuS
SplunkTrust
SplunkTrust

okay try admin and changeme which is the default. if this does not work make a backup of $SPLUNK_HOME/etc/passwd remove the same file and restart Splunk. After that you will be able to login using the default admin and changeme.
If you had any other users beside admin in $SPLUNK_HOME/etc/passwd simply copy/paste them back into the new $SPLUNK_HOME/etc/passwd file

antg334
Explorer

It is prompting me for a Splunk username and password. I tried using the local account but it states that the login failed. Where can I find the account information this is looking for?

0 Karma

MuS
SplunkTrust
SplunkTrust

do

 $SPLUNK_HOME\bin\splunk enable webserver
 $SPLUNK_HOME\bin\splunk start splunkweb

antg334
Explorer

It states that splunkweb is not running. I have tried splunk restart splunkweb but get the same message. I even tried splunk start splunkweb and received absolutely nothing from that.

0 Karma

MuS
SplunkTrust
SplunkTrust

Execute

$SPLUNK_HOME\bin\splunk status

Do you see splunkweb listed?

0 Karma

antg334
Explorer

I have done a majority of the steps you listed in your triage, except the tcpdump. What leads me to believe it lies in Splunk is that I was able to connect previously before I upgraded the version. This is on an Indexer.

0 Karma

linu1988
Champion

by any chance is it a forwarder installer? 😄

0 Karma

grijhwani
Motivator

Then you asked the wrong question. The issues that could possibly stop the page displaying are many and varied, and only a few relate to the Splunk installation itself.

Have you performed basic triage to isolate the problem? Are you directing your query to the right address and port? Are yo usure you can even reach the server? Have you performed a netstat on the server to see whether the process is attached to the correct port? Have you performed a tcpdump to ensure that your browser packets are reaching the server? What leads you to think the fault lies with Splunk?

antg334
Explorer

I have already downloaded the rpm, which is an older version, 6.0.3 and installed it on the server but I am not seeing Splunkweb within the installation. So whenever I try to connect to Splunkweb I always receive an unable to display this page.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...