Deployment Architecture

What servers does Splunk use?

msrkr
Explorer

I deployed Splunk in an AWS environment and want to know what servers Splunk uses?
like webserver, application server

0 Karma

woodcock
Esteemed Legend

Splunk runs a web-service on port 8000 which is a GUI front end to access it's REST API which does its work through the splunkd process running on the server.

0 Karma

lfedak_splunk
Splunk Employee
Splunk Employee

Hey @msrkr, if this answered your question don't forget to "Accept" the answer to award karma points 😄

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Splunk is a self-contained application. The core runs without a GUI and exposes a REST API to the world (accessible by default via port 8089). The Splunk UI uses this REST API. A built-in web server (CherryPy) is used to serve up the UI (by default via port 8000).
For a complete list of third-party software bundled with Splunk, see the documentation.

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...