Security

Binding splunk-web to an ip address - WARNING: web interface does not seem to be available!

ikulcsar
Communicator

Hello,

We have a distributed Splunk system. Every indexers have 2 IPs (ip1 and ip2) addresses (and 2 NICs, too). The goal is to bind the web interface to ip1 while keeping the ability to receive logs on both IPs.

I've already checked https://docs.splunk.com/Documentation/Splunk/latest/Admin/BindSplunktoanIP and serveral questions here with no luck.
When set server.socket_host setting in web.conf to ip1, and leave SPLUNK_BINDIP, mgmtHostPort on default I recieved this at Splunk startup.

Waiting for web server at http://127.0.0.1:8000 to be available............................................................................................................................................................................................................................................................................................................

WARNING: web interface does not seem to be available!

From 'ss -na' output:

LISTEN      0      128           <ip1>:8000                      *:*
UNCONN      0      0                   *:514                        *:*

Ip1 is not 127.0.0.1, so it will never succeed to connect... but logs can be recieved on any ip. System seems to operational.

How can I handle this warning, Is there a way to achieve my goal without an error?

About the system: Splunk v6.5.1 on 64bit linux, multiple search heads and indexers, no firewall.

Thanks,
Istvan

0 Karma
1 Solution

ikulcsar
Communicator

Hi,

I received information from tech support, This is a bug, they will fix it in one of the upcoming releases.

Regards,
István

View solution in original post

0 Karma

ikulcsar
Communicator

Hi,

I received information from tech support, This is a bug, they will fix it in one of the upcoming releases.

Regards,
István

0 Karma

ikulcsar
Communicator

Fixed in 6.6.3: https://docs.splunk.com/Documentation/Splunk/6.6.3/ReleaseNotes/6.6.3
Issue numbers: SPL-136496, SPL-141953, SPL-141956

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...