Getting Data In

Heavy forwarder with 2nics not communicating on 8089

nickstone
Path Finder

I have a heavy forwarder running 6.4.1 on CentOS 7 with 2 nics on seperate subnets (data and mgt) that won't communicate on port 8089.

In a netstat I can see that 8089 is listening but no comms.

When I disable one of the interface, everything works fine.

Any ideas?

0 Karma

ephemeric
Contributor

LOL! SELinux again.

grep "denied" /var/log/audit/audit.log
0 Karma

mtranchita
Communicator

Guessing that splunk is confused about what IP it should be using. I would try setting the IP for interface that you want use by setting SPLUNK_BINDIP= in the splunk-launch.conf.
Note that this conf file is not in apps but rather $SPLUNK_HOME/etc/splunk-launch.conf.
Double check the spec, http://docs.splunk.com/Documentation/Splunk/latest/Admin/Splunk-launchconf, for syntax.
Hope this helps!

0 Karma

nickstone
Path Finder

this will bind both 8089, 9997 AND web to that interface right? Web needs to be separated to mgt and not on data otherwise it defeats the purpose of segmentaton

0 Karma

mtranchita
Communicator

right, sorry.
Have you tried setting mgmtHostPort in web.conf?

0 Karma

nickstone
Path Finder

mgmtHostPort is set to localhost on port 8089

0 Karma

nickstone
Path Finder

never mind SElinux,....

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...