Splunk Dev

Bind separate IP for Web & Daemon

deyeo
Path Finder

My server has 2 IP addresses and i need to bind the splunk web to 1 IP and the splunk daemon to the other IP address.

i configure the server.socket_host setting in web.conf.

the splunk web indeed has bind to the IP address

However, when i modify $SPLUNK_HOME/etc/splunk-launch.conf to include the SPLUNK_BINDIP attribute and value, the splunk web is no longer bound to the IP that i specified in web.conf but is now bound to the IP i specified in splunk-launch.conf

How do i ultimately get to bind the web and daemon to 2 different IP addresses?

Tags (1)
1 Solution

deyeo
Path Finder

This is the reply i've gotten from Splunk Support:

I believe we cannot have this kind of feature at the moment, I can help to file an enhancement request for that if the product team will provide this kind of feature. I think it is worth having of the ports binding to 2 difference of IP addresses. Thanks for your suggestion.

View solution in original post

0 Karma

ppeterson
Path Finder

I have an issue doing this, I needed to bind the web UI on port 8000 but leave the rest of splunk listening on 127.0.0.1. I was able to accomplish this however when I start splunk it still shows that it is trying to start on 127.0.0.1:8000. Is this just an annoyan ce I'll need to live with?

Waiting for web server at http://127.0.0.1:8000 to be available...........................................................................server.socket_host...................................................................................................................................................................................................^C

0 Karma

mhorbul
Explorer

Is there any solution for that ? I want to have 8089 be listened from 127.0.0.1 but 8000 - from particular external IP.

0 Karma

deyeo
Path Finder

This is the reply i've gotten from Splunk Support:

I believe we cannot have this kind of feature at the moment, I can help to file an enhancement request for that if the product team will provide this kind of feature. I think it is worth having of the ports binding to 2 difference of IP addresses. Thanks for your suggestion.

0 Karma

ikulcsar
Communicator

Dear deyeo,

Is there any update in this topic?

I have a similar problem: need to bind splunk-web to a specific IP, while need to receive logs on all ip.

Thanks,
István

0 Karma

jrbeers717
Engager

I'm having trouble with this as well and would love an answer.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...