Getting Data In

splunkforwarder issue solaris 10

filter
Engager

I installed splunkforwarder for Sparc without any errors and started the daemon. When I try top connect with in browser (http://hostname:8089 or http://hostname:8000) I get "Page can not be displayed"

Instalation and app start-ul look OK:

Splunk> Take the sh out of IT.

Checking prerequisites...
        Checking mgmt port [8089]: open
        Checking conf files for typos...
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done.
[:root:/opt/splunkforwarder/bin]50 pkginfo -l splunkforwarder
   PKGINST:  splunkforwarder
      NAME:  Splunk Agent
  CATEGORY:  application
      ARCH:  sparc
   VERSION:  4.3.1
   BASEDIR:  /opt
    VENDOR:  Splunk Inc.
      DESC:  Splunk is the search engine for Operational Intelligence.
    PSTAMP:  epm20120302050241
  INSTDATE:  Apr 13 2012 03:39
    STATUS:  completely installed
     FILES:      236 installed pathnames
                  48 directories
                  56 executables
              113542 blocks used (approx)

Any idea ?

0 Karma

kristian_kolb
Ultra Champion

The Splunk Universal Forwarder is an lightweight agent that does not have a user-friendly GUI running on (default) port 8000. Simple as that.

What it does have is REST manangement interface running on https://your_ip:8089. However you will need to authenticate with your splunk user credentials (yes forwarders can have users too). But the default admin/changeme credentials are blocked from connecting to a forwarder remotely. You can reconfigure your forwarder to accept the default credentials, but it is probably safer to just change the admin password, right?

Hope this helps,

K

0 Karma

MickSheppard
Path Finder

The forwarder doesn't have a webserver for you to connect to.

filter
Engager

I was afraid of that. Thank you for taking the time to confirm.

0 Karma

marg224
New Member

Ummmmm....same problem here, but, maybe a little more info as to why? Install directions were followed, but, no port 8000 was set up and nowhere during the install was there anywhere to input that. Sooooo....any suggestions????

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...