Splunk Enterprise

Error message on Splunk

hordoffa1970
New Member

Encountered the following error while trying to save: Failed to create. Configuration for port 9997 already exists. I am getting this message on Splunk when I try to configure and save the listening port

Labels (1)
0 Karma

kknairr
Contributor

@hordoffa1970 The error message “Failed to create. Configuration for port 9997 already exists” means the receiving port you’re trying to configure is already set up somewhere in your Splunk configuration. Port 9997 is the default receiving port for Splunk indexers, so if it’s already enabled, trying to add it again will trigger this message.

You can check existing receiving configuration In Splunk Web by navigating to: 
Settings → Forwarding and Receiving → Configure Receiving

You should see port 9997 already listed. If 9997 is already active, you don’t need to add it again. Just confirm it’s listening.

> Giving Karma & Marking the answer helps others find solutions faster!

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @hordoffa1970 

As the error suggests, it looks like something is already listening on port 9997. 

What exactly is it you are trying to do? Do you already have an inputs.conf configured to receive data (or is something else on your system using port 9997)?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...