Security

Splunk no longer listens on SSL-enable port 9997 after upgrade to Splunk 5

dshakespeare_sp
Splunk Employee
Splunk Employee

Since upgrading from Splunk 4.3 to Splunk 5.0 customer reports that they ate unable to index data because the SSL-enabled input port doesn't work. The following errors are seen in splunkd.log

INFO SSLCommon - SSL compression not turned on
INFO TcpInputConfig - IPv6 port 9997 is reserved for splunk 2 splunk (SSL)
INFO TcpInputConfig - IPv6 port 9997 is compressed
ERROR TcpInputConfig - SSL context not found. Will not open splunk 2 splunk (SSL) IPv4 port 9997

Tags (1)

dshakespeare_sp
Splunk Employee
Splunk Employee

The problem occurs if "listenOnIPv6 = yes" is set in server.conf.
A workaround is to set "listenOnIPv6 = no" in server.conf

Splunk are aware of this issue. see
http://docs.splunk.com/Documentation/Splunk/5.0/ReleaseNotes/KnownIssues#Data_input_issues

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...