Getting Data In

splunkforwarder issue solaris 10

filter
Engager

I installed splunkforwarder for Sparc without any errors and started the daemon. When I try top connect with in browser (http://hostname:8089 or http://hostname:8000) I get "Page can not be displayed"

Instalation and app start-ul look OK:

Splunk> Take the sh out of IT.

Checking prerequisites...
        Checking mgmt port [8089]: open
        Checking conf files for typos...
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done.
[:root:/opt/splunkforwarder/bin]50 pkginfo -l splunkforwarder
   PKGINST:  splunkforwarder
      NAME:  Splunk Agent
  CATEGORY:  application
      ARCH:  sparc
   VERSION:  4.3.1
   BASEDIR:  /opt
    VENDOR:  Splunk Inc.
      DESC:  Splunk is the search engine for Operational Intelligence.
    PSTAMP:  epm20120302050241
  INSTDATE:  Apr 13 2012 03:39
    STATUS:  completely installed
     FILES:      236 installed pathnames
                  48 directories
                  56 executables
              113542 blocks used (approx)

Any idea ?

0 Karma

kristian_kolb
Ultra Champion

The Splunk Universal Forwarder is an lightweight agent that does not have a user-friendly GUI running on (default) port 8000. Simple as that.

What it does have is REST manangement interface running on https://your_ip:8089. However you will need to authenticate with your splunk user credentials (yes forwarders can have users too). But the default admin/changeme credentials are blocked from connecting to a forwarder remotely. You can reconfigure your forwarder to accept the default credentials, but it is probably safer to just change the admin password, right?

Hope this helps,

K

0 Karma

MickSheppard
Path Finder

The forwarder doesn't have a webserver for you to connect to.

filter
Engager

I was afraid of that. Thank you for taking the time to confirm.

0 Karma

marg224
New Member

Ummmmm....same problem here, but, maybe a little more info as to why? Install directions were followed, but, no port 8000 was set up and nowhere during the install was there anywhere to input that. Sooooo....any suggestions????

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...