Security

Splunk no longer listens on SSL-enable port 9997 after upgrade to Splunk 5

dshakespeare_sp
Splunk Employee
Splunk Employee

Since upgrading from Splunk 4.3 to Splunk 5.0 customer reports that they ate unable to index data because the SSL-enabled input port doesn't work. The following errors are seen in splunkd.log

INFO SSLCommon - SSL compression not turned on
INFO TcpInputConfig - IPv6 port 9997 is reserved for splunk 2 splunk (SSL)
INFO TcpInputConfig - IPv6 port 9997 is compressed
ERROR TcpInputConfig - SSL context not found. Will not open splunk 2 splunk (SSL) IPv4 port 9997

Tags (1)

dshakespeare_sp
Splunk Employee
Splunk Employee

The problem occurs if "listenOnIPv6 = yes" is set in server.conf.
A workaround is to set "listenOnIPv6 = no" in server.conf

Splunk are aware of this issue. see
http://docs.splunk.com/Documentation/Splunk/5.0/ReleaseNotes/KnownIssues#Data_input_issues

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...