Splunk Enterprise

Error message on Splunk

hordoffa1970
New Member

Encountered the following error while trying to save: Failed to create. Configuration for port 9997 already exists. I am getting this message on Splunk when I try to configure and save the listening port

Labels (1)
0 Karma

kknairr
Contributor

@hordoffa1970 The error message “Failed to create. Configuration for port 9997 already exists” means the receiving port you’re trying to configure is already set up somewhere in your Splunk configuration. Port 9997 is the default receiving port for Splunk indexers, so if it’s already enabled, trying to add it again will trigger this message.

You can check existing receiving configuration In Splunk Web by navigating to: 
Settings → Forwarding and Receiving → Configure Receiving

You should see port 9997 already listed. If 9997 is already active, you don’t need to add it again. Just confirm it’s listening.

> Giving Karma & Marking the answer helps others find solutions faster!

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @hordoffa1970 

As the error suggests, it looks like something is already listening on port 9997. 

What exactly is it you are trying to do? Do you already have an inputs.conf configured to receive data (or is something else on your system using port 9997)?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...