Bind Splunk to an IP
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Bind Splunk to an IP
You can force Splunk to bind its ports to a specified IP address.
Temporarily
To make this a temporary change, set the environment variable SPLUNK_BINDIP=<ipaddress> before starting Splunk.
Permanently
If you want this to be a permanent change in your working environment, modify $SPLUNK_HOME/etc/splunk-launch.conf to include the SPLUNK_BINDIP attribute and <ipaddress> value. For example, to bind Splunk ports to 127.0.0.1, splunk-launch.conf should read:
# Modify the following line to suit the location of your Splunk install. # If unset, Splunk will use the parent of the directory this configuration # file was found in # # SPLUNK_HOME=/opt/splunk SPLUNK_BINDIP=127.0.0.1
This will affect the binding address of all ports opened by splunk and splunkweb, including the http server, and network inputs.
Note: You can also use splunk-launch.conf to define $SPLUNK_HOME and $SPLUNK_DB.
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.