Splunk Dev

Bind separate IP for Web & Daemon

deyeo
Path Finder

My server has 2 IP addresses and i need to bind the splunk web to 1 IP and the splunk daemon to the other IP address.

i configure the server.socket_host setting in web.conf.

the splunk web indeed has bind to the IP address

However, when i modify $SPLUNK_HOME/etc/splunk-launch.conf to include the SPLUNK_BINDIP attribute and value, the splunk web is no longer bound to the IP that i specified in web.conf but is now bound to the IP i specified in splunk-launch.conf

How do i ultimately get to bind the web and daemon to 2 different IP addresses?

Tags (1)
1 Solution

deyeo
Path Finder

This is the reply i've gotten from Splunk Support:

I believe we cannot have this kind of feature at the moment, I can help to file an enhancement request for that if the product team will provide this kind of feature. I think it is worth having of the ports binding to 2 difference of IP addresses. Thanks for your suggestion.

View solution in original post

0 Karma

ppeterson
Path Finder

I have an issue doing this, I needed to bind the web UI on port 8000 but leave the rest of splunk listening on 127.0.0.1. I was able to accomplish this however when I start splunk it still shows that it is trying to start on 127.0.0.1:8000. Is this just an annoyan ce I'll need to live with?

Waiting for web server at http://127.0.0.1:8000 to be available...........................................................................server.socket_host...................................................................................................................................................................................................^C

0 Karma

mhorbul
Explorer

Is there any solution for that ? I want to have 8089 be listened from 127.0.0.1 but 8000 - from particular external IP.

0 Karma

deyeo
Path Finder

This is the reply i've gotten from Splunk Support:

I believe we cannot have this kind of feature at the moment, I can help to file an enhancement request for that if the product team will provide this kind of feature. I think it is worth having of the ports binding to 2 difference of IP addresses. Thanks for your suggestion.

0 Karma

ikulcsar
Communicator

Dear deyeo,

Is there any update in this topic?

I have a similar problem: need to bind splunk-web to a specific IP, while need to receive logs on all ip.

Thanks,
István

0 Karma

jrbeers717
Engager

I'm having trouble with this as well and would love an answer.

Thanks!

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...