Splunk Enterprise

Splunk is bind to an IP 127.0.0.1

Explorer

We have below stanza in /opt/splunk/etc/splunk-launch.conf file of the heavy forwarder to avoid any security risks. This means the heavy forwarder is bind to localhost only.

SPLUNK_BINDIP=127.0.0.1

However, we want to receive the data on this heavy forwarder from a specific machine using the HTTP event collector app.

Is there any way to receive the events without removing this stanza? Has anyone else faced a similar situation?

Labels (1)
0 Karma