Installation

Why can't I access Splunk web interface?

chandra777
Loves-to-Learn

Hi,

I am unable to access splunk web interface.

I have taken 1 ec2 instance from aws  Red Hat Enterprise Linux 7 with High Availability

installed  the splunk in /opt

[root@ip-172-31-82-137 splunk]# netstat -an | grep 8000
tcp 0 0 0.0.0.0:8000 0.0.0.0:* LISTEN

 

[root@ip-172-31-82-137 splunk]# sestatus
SELinux status: disabled
[root@ip-172-31-82-137 splunk]#

sudo ./splunk restart
Stopping splunkd...
Shutting down. Please wait, as this may take a few minutes.
.. [ OK ]
Stopping splunk helpers...
[ OK ]
Done.

Splunk> Take the sh out of IT.

Checking prerequisites...
Checking http port [8000]: open
Checking mgmt port [8089]: open
Checking appserver port [127.0.0.1:8065]: open
Checking kvstore port [8191]: open
Checking configuration... Done.
Checking critical directories... Done
Checking indexes...
Validated: _audit _configtracker _internal _introspection _metrics _metrics_rollup _telemetry _thefishbucket history main summary
Done
Checking filesystem compatibility... Done
Checking conf files for problems...
Done
Checking default conf files for edits...
Validating installed files against hashes from '/opt/splunk/splunk-9.0.0-6818ac46f2ec-linux-2.6-x86_64-manifest'
All installed files intact.
Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
PYTHONHTTPSVERIFY is set to 0 in splunk-launch.conf disabling certificate validation for the httplib and urllib libraries shipped with the embedded Python interpreter; must be set to "1" for increased security
Done
[ OK ]

Waiting for web server at http://127.0.0.1:8000 to be available.............. Done


If you get stuck, we're here to help.
Look for answers here: http://docs.splunk.com

The Splunk web interface is at http://ip-172-31-82-137.ec2.internal:8000

******************************************************************************************

I see error under web_service log

2022-07-16 06:55:45,844 INFO [62d260ef597f205fe25d10] root:733 - CONFIG: error_page.default (method):
<bound method ErrorController.handle_error of
<splunk.appserver.mrsparkle.controllers.error.ErrorController object at 0x7f205e9e6090>>

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@chandra777 - It seems firewall/network issue.

 

I hope this helps!!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...