Security

Running Splunkweb on localhost

mundus
Path Finder

What is the best practice for making Splunkweb listen only on localhost or 127.0.0.1?

Thx.

Craig

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

The "best" practice is up to you to determine, but you can make the SplunkWeb process only listen by setting server.sockethost = 127.0.0.1 in the web.conf file. If this is a concern to you, you may also want to use iptables or another firewall.

tmcwaters
Engager

Slight correction. The setting is server.socket_host not server.sockethost
Also setting it as
server.socket_host = localhost
allows for IPv6 support vs 127.0.0.1 which only works in IPv4

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...