Splunk Enterprise starts, but why is my connection refused trying to access Splunk Web in my browser?

New Member

I just installed Splunk Enterprise 6.0 and all went swimmingly. However, my connection is refused when trying to go to it in my browser. What am I missing?

Splunk> 4TW

Checking prerequisites...   Checking
http port [8000]: open  Checking mgmt
port [8089]: open   Checking
configuration...  Done.         Creating:
/opt/splunk/var/lib/splunk      Creating:
/opt/splunk/var/run/splunk      Creating:
    Checking critical directories...    Done
    Checking indexes...         Validated:
_audit _blocksignature _internal _thefishbucket history main summary    Done New certs have been generated in
'/opt/splunk/etc/auth'.     Checking
filesystem compatibility...  Done
    Checking conf files for typos... 
    Done All preliminary checks passed.

Starting splunk server daemon
(splunkd)...   Done
                                                           [  OK  ] Starting splunkweb... 
Generating certs for splunkweb server
Generating a 1024 bit RSA private key
........++++++ ...............++++++
writing new private key to
----- Signature ok subject=/CN=localhost.localdomain/O=SplunkUser
Getting CA Private Key writing RSA key
                                                           [  OK  ] Done

If you get stuck, we're here to help. 
Look for answers here:

The Splunk web interface is at
0 Karma

Path Finder

Check your management port numbers.

0 Karma

Path Finder

Taking the fact that it worked fine with firewall disabled, I think you just need to open the right port for this. In this case, 8000.
Here is a good port digram


0 Karma


Check that you've got the protocol, host name, port correct in the browser. If wrong, correct and try again.
Check that you can establish a connection, e.g. telnet to the host and port. If not, talk to network administration to fix.

That being said, go grab 6.3 - it's significantly improved over 6.0.

0 Karma

New Member

I stopped the firewall and it worked fine - so something in my firewall settings is doing this.

I am trying to help a customer using our app and they aren't willing to upgrade to 6.3 yet for some reason - so I'm trying ti troubleshoot the older version with them. I'm just running 6.0 in a VM for these purposes.

0 Karma
Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...