<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port Documentation in Security</title>
    <link>https://community.splunk.com/t5/Security/Port-Documentation/m-p/573044#M15689</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;splunk has published this too in docs, but I cannot found it now &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.aplura.com/splunk-best-practices/" target="_blank"&gt;https://www.aplura.com/splunk-best-practices/&lt;/A&gt;&amp;nbsp;This doc contains also picture and explanations of those.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Fri, 29 Oct 2021 22:30:56 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-10-29T22:30:56Z</dc:date>
    <item>
      <title>Port Documentation</title>
      <link>https://community.splunk.com/t5/Security/Port-Documentation/m-p/573040#M15688</link>
      <description>&lt;P&gt;We have a &lt;U&gt;standalone&lt;/U&gt; install which has to follow specific guidance and documentation. Without getting much into things,&amp;nbsp; I need to document each port open and if certain ones don't already have a vulnerability assessment on file I need to generate a local report on what the port is for and how its utilized in the system(s).&lt;/P&gt;&lt;P&gt;My clients have splunk installed but don't tap into a lot of its power currently. Therefore I expect a lot of the extra ports can be turned off (at least for now) and save me a lot of paperwork.&lt;/P&gt;&lt;P&gt;This brings me to port 8065 and 8191.&lt;/P&gt;&lt;P&gt;8065, a local listening port that is tied to the splunk appserver. Problem is I can't find what Splunk is using this for exactly outside "app server".&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If we don't utilize Splunk apps is this required? If we did what does this port provide and why would it be required?&lt;/LI&gt;&lt;LI&gt;When are calls made to it?&lt;/LI&gt;&lt;LI&gt;How would I turn it off in version 8 if I don't need it?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;8191 is used for app kv store.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If apps are not utilized, can this be turned off?&lt;/LI&gt;&lt;LI&gt;If so how?&lt;/LI&gt;&lt;LI&gt;If apps are not utilized this seems like it wouldn't be required.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 21:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Port-Documentation/m-p/573040#M15688</guid>
      <dc:creator>dcsteve24</dc:creator>
      <dc:date>2021-10-29T21:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Port Documentation</title>
      <link>https://community.splunk.com/t5/Security/Port-Documentation/m-p/573044#M15689</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;splunk has published this too in docs, but I cannot found it now &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.aplura.com/splunk-best-practices/" target="_blank"&gt;https://www.aplura.com/splunk-best-practices/&lt;/A&gt;&amp;nbsp;This doc contains also picture and explanations of those.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 22:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Port-Documentation/m-p/573044#M15689</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-10-29T22:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Port Documentation</title>
      <link>https://community.splunk.com/t5/Security/Port-Documentation/m-p/683467#M17754</link>
      <description>&lt;P&gt;Hi! I know I'm late but I've always wondered this as well... From the &lt;STRONG&gt;Components and their relationship with the network&lt;/STRONG&gt; section of the &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/InheritedDeployment/Ports" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Inherit a Splunk Enterprise Deployment&lt;/STRONG&gt;&lt;/A&gt; documentation, this is loopback communication, meaning you won't need to open any ports. Splunk is talking to the local KV Store database (mongod).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="20240405_123937.png" style="width: 696px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30279iEF6619DCF21D90A1/image-size/large?v=v2&amp;amp;px=999" role="button" title="20240405_123937.png" alt="20240405_123937.png" /&gt;&lt;/span&gt;If I run an lsof for open ports, I see the following all occurring over the loopback interface (8065 shows a similar result, only showing Python as the listening service):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="20240405_125005.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30278i02EE925E925E6B97/image-size/large?v=v2&amp;amp;px=999" role="button" title="20240405_125005.png" alt="20240405_125005.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 17:56:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Port-Documentation/m-p/683467#M17754</guid>
      <dc:creator>jmartin_pro</dc:creator>
      <dc:date>2024-04-05T17:56:40Z</dc:date>
    </item>
  </channel>
</rss>

