Port 8088: Hadoop YARN ResourceManager web UI and Splunk HTTP Event Collector
IANA assigns 8088 over TCP and UDP to radan-http (Radan HTTP), but the port is better known as the default for two unrelated HTTP services. Apache Hadoop sets the YARN ResourceManager web application address to port 8088, and Splunk's HTTP Event Collector (HEC) listens on 8088 by default to receive application events.
Port Details
Security Exposure
Hadoop's default hadoop.security.authentication value is "simple", which the Secure Mode guide defines as no authentication, and the guide expects operators to restrict all network access to a cluster that has not been secured. Alibaba Cloud reported a Kinsing botnet variant that spread through unauthorized access to the Hadoop YARN REST API and the YARN RPC service, then downloaded and started cryptocurrency mining software. On Splunk, HEC accepts events from any client that presents a valid token, so a leaked token is enough to write events into the index.
Hardening
- +Block 8088 at the perimeter and allow it only from the networks that administer the cluster or submit jobs.
- +Configure Kerberos authentication for Hadoop as described in the Hadoop Secure Mode guide instead of running in the default simple mode.
- +Turn on HTTPS for the YARN web interfaces with the yarn.http.policy setting.
- +Enable SSL on the Splunk HEC listener and disable HEC tokens that are no longer in use.
Monitoring
Review ResourceManager application submissions for unknown users or unexpected application names, and alert on inbound 8088 connections from outside the cluster's management networks. For HEC, watch for events arriving under tokens or source addresses that do not match known senders.
Tools for Auditing and Monitoring YARN / Splunk HEC
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
What runs on port 8088?→
The IANA registry lists radan-http for 8088. In practice, Hadoop YARN uses it for the ResourceManager web application, and Splunk uses it as the default HTTP Event Collector port.
Is port 8088 TCP or UDP?→
IANA lists both TCP and UDP for radan-http. YARN and Splunk HEC both run over HTTP or HTTPS, which uses TCP.
Should port 8088 be open to the internet?→
Not for a Hadoop cluster in its default configuration. The Hadoop documentation says a cluster without Kerberos security depends on restricting network access to keep attackers out.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8088 is not guaranteed to be YARN / Splunk HEC. Exploited-in-the-wild data from the CISA KEV catalog (CC0).