I am using Splunk Enterprise 6.6.1 and there is a security vulnerability that exploits Splunk Web that is resolved in 6.6.3. I go to my services running and there is a "splunkweb (for legacy purposes only)" service that is not running, so it appears that we do not use splunk web, although I can still access splunk from the web interface. How can I find out for sure if I am exposed to this vulnerability?
if you're accessing splunk on port 8000, you are running splunkweb on port 8000. unless you deliberately turn it off in web.conf, splunkweb starts with Splunk.
in order to find out for sure, you would have to run intrusion tests on splunkweb, following the criteria of your specific vulnerability.