<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk DB connect in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90296#M14180</link>
    <description>&lt;P&gt;Did a trace and found the answer myself - random high port:&lt;BR /&gt;
netstat -an | grep 172.27.67.174&lt;BR /&gt;
tcp        0      1 ::ffff:172.27.91.38:41717   ::ffff:172.27.67.174:3306   SYN_SENT&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2013 13:24:03 GMT</pubDate>
    <dc:creator>ffrig</dc:creator>
    <dc:date>2013-10-09T13:24:03Z</dc:date>
    <item>
      <title>Splunk DB connect</title>
      <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90291#M14175</link>
      <description>&lt;P&gt;I have a firewall between my indexer and MySLQ DB. What port(s) does the indexer use to make connections and queries? It is just 8000, 8089 or others? I'm connecting through to the standard 3306 port for MySQL. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 12:16:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90291#M14175</guid>
      <dc:creator>ffrig</dc:creator>
      <dc:date>2013-10-09T12:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect</title>
      <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90292#M14176</link>
      <description>&lt;P&gt;The indexer would initiate a connection from its side to the MySQL database, on whatever port the database is running. In your case, that's 3306.&lt;/P&gt;

&lt;P&gt;Have you tried this and encountered an issue?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 12:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90292#M14176</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-10-09T12:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect</title>
      <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90293#M14177</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;You only need the 3306, as long as you don't install a forwarder in the db server.&lt;/P&gt;

&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 12:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90293#M14177</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2013-10-09T12:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect</title>
      <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90294#M14178</link>
      <description>&lt;P&gt;You'll need to allow the connection from the Splunk instance to the DB, which in your case seems to be port 3306.&lt;/P&gt;

&lt;P&gt;Port 8000 is the default port where splunkweb is running. It has nothing to do with DBConnect. But of course you'll have to allow inbound traffic to the Splunk server on that port for users connecting with their browsers.&lt;/P&gt;

&lt;P&gt;Port 8089 is used by various splunk instances (forwarders, indexers, search heads etc)to talk to each other (deployment traffic, distributing searches etc).&lt;/P&gt;

&lt;P&gt;Port 9997 is commonly used for sending log traffic from forwarders to indexers.&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 12:26:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90294#M14178</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-10-09T12:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect</title>
      <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90295#M14179</link>
      <description>&lt;P&gt;Thanks all, but I was after what the source port would be from the indexer to the DB server. Wasn't sure if this was a random high port or from Splunk Web?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 12:53:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90295#M14179</guid>
      <dc:creator>ffrig</dc:creator>
      <dc:date>2013-10-09T12:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect</title>
      <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90296#M14180</link>
      <description>&lt;P&gt;Did a trace and found the answer myself - random high port:&lt;BR /&gt;
netstat -an | grep 172.27.67.174&lt;BR /&gt;
tcp        0      1 ::ffff:172.27.91.38:41717   ::ffff:172.27.67.174:3306   SYN_SENT&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 13:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90296#M14180</guid>
      <dc:creator>ffrig</dc:creator>
      <dc:date>2013-10-09T13:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk DB connect</title>
      <link>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90297#M14181</link>
      <description>&lt;P&gt;Oh, so you needed the &lt;EM&gt;source&lt;/EM&gt; port.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2013 13:27:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-DB-connect/m-p/90297#M14181</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-10-09T13:27:21Z</dc:date>
    </item>
  </channel>
</rss>

