Deployment Architecture

What servers does Splunk use?

msrkr
Explorer

I deployed Splunk in an AWS environment and want to know what servers Splunk uses?
like webserver, application server

0 Karma

woodcock
Esteemed Legend

Splunk runs a web-service on port 8000 which is a GUI front end to access it's REST API which does its work through the splunkd process running on the server.

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @msrkr, if this answered your question don't forget to "Accept" the answer to award karma points 😄

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Splunk is a self-contained application. The core runs without a GUI and exposes a REST API to the world (accessible by default via port 8089). The Splunk UI uses this REST API. A built-in web server (CherryPy) is used to serve up the UI (by default via port 8000).
For a complete list of third-party software bundled with Splunk, see the documentation.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...