Installation

Accessing Splunk Enterprise for Azure after Installation

stevenield
New Member

I have just installed Splunk Enterprise through the Azure Marketplace. The deployment has completed and I haven't changed any of the default security settings. I cannot access the application through a browser using http://[publicip]:8000; I get a ERR_CONNECTION_REFUSED in Chrome. I have also tried connecting through Telnet and I get a "connect failed" reposonse. I have checked and the Incoming Security Rule exists for TCP port 8000.

Has anyone else had this problem?

Is this a problem with the standard installation from the Marketplace?

What additional step do I need to take to get the access I need?

Tags (1)
0 Karma
1 Solution

rarsan_splunk
Splunk Employee
Splunk Employee

Splunk Enterprise for Azure can be accessed at https://{domainName}.{location}.cloudapp.azure.com. For example, if the deployment is created in the West US region with parameter domainName set to "example", you can access it at https://example.westus.cloudapp.azure.com using Splunk username admin and the user-specified Splunk password.

The URL can also be found as an output of the actual ARM deployment. From Azure portal, browse to 'Resource Groups', select the resource group you specified when deploying Splunk, click under 'last deployment', and look for a deployment that starts with 'splunk.splunk-enterprise-previewbyol'. Splunk URL should be listed as one of the outputs.

While the URL format above is documented on Azure Marketplace page for Splunk, we understand that users should be directly notified of this URL upon completion of the deployment from within the Azure portal. We have reported this to the Azure Marketplace team.

View solution in original post

0 Karma

rarsan_splunk
Splunk Employee
Splunk Employee

Splunk Enterprise for Azure can be accessed at https://{domainName}.{location}.cloudapp.azure.com. For example, if the deployment is created in the West US region with parameter domainName set to "example", you can access it at https://example.westus.cloudapp.azure.com using Splunk username admin and the user-specified Splunk password.

The URL can also be found as an output of the actual ARM deployment. From Azure portal, browse to 'Resource Groups', select the resource group you specified when deploying Splunk, click under 'last deployment', and look for a deployment that starts with 'splunk.splunk-enterprise-previewbyol'. Splunk URL should be listed as one of the outputs.

While the URL format above is documented on Azure Marketplace page for Splunk, we understand that users should be directly notified of this URL upon completion of the deployment from within the Azure portal. We have reported this to the Azure Marketplace team.

0 Karma

gblock_splunk
Splunk Employee
Splunk Employee

Have you tried https?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...