Splunk Dev

Bind separate IP for Web & Daemon

deyeo
Path Finder

My server has 2 IP addresses and i need to bind the splunk web to 1 IP and the splunk daemon to the other IP address.

i configure the server.socket_host setting in web.conf.

the splunk web indeed has bind to the IP address

However, when i modify $SPLUNK_HOME/etc/splunk-launch.conf to include the SPLUNK_BINDIP attribute and value, the splunk web is no longer bound to the IP that i specified in web.conf but is now bound to the IP i specified in splunk-launch.conf

How do i ultimately get to bind the web and daemon to 2 different IP addresses?

Tags (1)
1 Solution

deyeo
Path Finder

This is the reply i've gotten from Splunk Support:

I believe we cannot have this kind of feature at the moment, I can help to file an enhancement request for that if the product team will provide this kind of feature. I think it is worth having of the ports binding to 2 difference of IP addresses. Thanks for your suggestion.

View solution in original post

0 Karma

ppeterson
Path Finder

I have an issue doing this, I needed to bind the web UI on port 8000 but leave the rest of splunk listening on 127.0.0.1. I was able to accomplish this however when I start splunk it still shows that it is trying to start on 127.0.0.1:8000. Is this just an annoyan ce I'll need to live with?

Waiting for web server at http://127.0.0.1:8000 to be available...........................................................................server.socket_host...................................................................................................................................................................................................^C

0 Karma

mhorbul
Explorer

Is there any solution for that ? I want to have 8089 be listened from 127.0.0.1 but 8000 - from particular external IP.

0 Karma

deyeo
Path Finder

This is the reply i've gotten from Splunk Support:

I believe we cannot have this kind of feature at the moment, I can help to file an enhancement request for that if the product team will provide this kind of feature. I think it is worth having of the ports binding to 2 difference of IP addresses. Thanks for your suggestion.

0 Karma

ikulcsar
Communicator

Dear deyeo,

Is there any update in this topic?

I have a similar problem: need to bind splunk-web to a specific IP, while need to receive logs on all ip.

Thanks,
István

0 Karma

jrbeers717
Engager

I'm having trouble with this as well and would love an answer.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...