Yeah, think I figured this out myself.
if
SPLUNK_BINDIP=127.0.0.1
is set in /opt/splunk/etc/splunk-launch.conf (linux example)
Then it seems all the other listen functions are set to the same localhost.
I've undone this feature and started to firewall off the management port etc.
Happy days.
... View more