Security

Splunk no longer listens on SSL-enable port 9997 after upgrade to Splunk 5

dshakespeare_sp
Splunk Employee
Splunk Employee

Since upgrading from Splunk 4.3 to Splunk 5.0 customer reports that they ate unable to index data because the SSL-enabled input port doesn't work. The following errors are seen in splunkd.log

INFO SSLCommon - SSL compression not turned on
INFO TcpInputConfig - IPv6 port 9997 is reserved for splunk 2 splunk (SSL)
INFO TcpInputConfig - IPv6 port 9997 is compressed
ERROR TcpInputConfig - SSL context not found. Will not open splunk 2 splunk (SSL) IPv4 port 9997

Tags (1)

dshakespeare_sp
Splunk Employee
Splunk Employee

The problem occurs if "listenOnIPv6 = yes" is set in server.conf.
A workaround is to set "listenOnIPv6 = no" in server.conf

Splunk are aware of this issue. see
http://docs.splunk.com/Documentation/Splunk/5.0/ReleaseNotes/KnownIssues#Data_input_issues

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...