Security

Which SSL Configurations Affect Which Port

phoenixdigital
Builder

I was hoping to get some clarification on this as there is no specific information that I could find in the documentation.

We obviously have these main ports in use for most Splunk installations.

  • Port 8000 - Splunk Web interface
  • Port 8089 - Splunk internal comms
  • Port 9997 - Splunk receiving

Would this graphic I put together accurately describe which .conf configurations affect each of the above?

alt text

I know there used to be some overlap with the some of the SSL configurations in server.conf which impact port 8000 but in recent Splunk releases it appears to have been separated out and compartmentalised to be contained in web.conf

Is there something missing from my diagram?

Are there any server.conf settings still affect the Splunk web on 8000 at all?

Thanks

Tags (2)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

per my knowledge your understandings are clear and good.
let me check again..

PS - maybe, you could have added the image directly, instead of imgur.

0 Karma

phoenixdigital
Builder

Yeah there is still confusion amongst some of our engineers (and splunk support) who are convinced server.conf settings can affect the port 8000. We are not sure which is right yet.

Notably things like cipherSuite, sslVersions and sslVersionsForClient.

Thanks for the tip. I forgot you could add images directly (fixed it up)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...