Splunk Enterprise

Splunk not starting with 8089

project9433
Engager

Recently I had installed splunk 6.5.1 in a new box and I wanted to configure that as Indexer instance. So that later I can include it in an Indexer cluster. Now after accepting license, splunk is not getting started. It says the management 8089 is used and do you want to change the port . I thoroughly checked with the Linux team and myself the port is not used-up, but still the Splunk is not able to start with the port 8089.

One strange observation was, immediately after I accept splunk and start it, then I get 8089 port issues pop-up. Now the very next moment, I did netstat the 8089 was shown as used up by my Deployment server. After 5 sec I did again the netstat the port was shown as unused. Though I have no setting for Depl server in my new Indexer box.

It is like stomping, the splunk tries to start using 8089 and then says it is used up(none other than splunk) and then after few min I dont see the port used anymore (splunk releases the port)

Tags (1)
0 Karma
1 Solution

ryanhast
Explorer

Make sure that your server is not also running a Splunk forwarder.
1. Uninstall then reinstall Splunk.

View solution in original post

hardikJsheth
Motivator

Did you make any change to any of the configurations files in Splunk before starting??

0 Karma

ryanhast
Explorer

Make sure that your server is not also running a Splunk forwarder.
1. Uninstall then reinstall Splunk.

project9433
Engager

Yes, I did realize after reading this post that there was a splunkforwarder running in the box. After I stopped it, I was able to run splunk with 8089 port. The strange thing was, the netstat did not show the port usage by forwarder. Anyways, Thanks you Ryan you rock!

0 Karma

10306629
New Member

yes i have reinstall splunk but still the Splunk is not able to start with the port 8089

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...