<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are the ports that I need to open? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62971#M12640</link>
    <description>&lt;P&gt;Many thanks for sharing. this is very useful, clear. &lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2019 05:27:17 GMT</pubDate>
    <dc:creator>balsa3d</dc:creator>
    <dc:date>2019-09-30T05:27:17Z</dc:date>
    <item>
      <title>What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62934#M12603</link>
      <description>&lt;P&gt;Hi, for Splunk to work properly, what are the ports that I need to open?&lt;/P&gt;
&lt;P&gt;Can anyone specify the inbound ports and outbound ports?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 21:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62934#M12603</guid>
      <dc:creator>antoaravinth</dc:creator>
      <dc:date>2020-11-04T21:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62935#M12604</link>
      <description>&lt;P&gt;defaults are &lt;BR /&gt;
9997 for forwarders to the Splunk indexer.&lt;BR /&gt;
8000 for clients to the Splunk Search page&lt;BR /&gt;
8089 for splunkd (also used by deployment server).&lt;/P&gt;

&lt;P&gt;All of these can be changed if desired.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2012 15:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62935#M12604</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-09-17T15:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62936#M12605</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have similar questions, but I need a bit more detail about direction.&lt;/P&gt;

&lt;P&gt;Is the splunk forwarder port 9997 tcp/udp from agent to indexer ?&lt;BR /&gt;
Is the splunk management port 8089 tcp only and from indexer/deployment server to agent or bidirectional?&lt;/P&gt;

&lt;P&gt;Cheers&lt;/P&gt;

&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2012 22:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62936#M12605</guid>
      <dc:creator>andyfry_nec</dc:creator>
      <dc:date>2012-10-18T22:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62937#M12606</link>
      <description>&lt;P&gt;8089 for the deployment server is only needed from the client to the deployment server.  Client being indexer, UF, etc.&lt;BR /&gt;
9997 from the forwarder to the indexer. No connection is needed back from the indexers.&lt;BR /&gt;
8089 is also used from a Search Head to your indexers. Again only single direction.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2012 22:23:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62937#M12606</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2012-10-18T22:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62938#M12607</link>
      <description>&lt;P&gt;On my forwarders, I see bi-directional data flowing on port 9997 between the forwarders and the indexers (using tcpdump src port 9997 and tcpdump dst port 9997)&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 15:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62938#M12607</guid>
      <dc:creator>hokie1999</dc:creator>
      <dc:date>2013-02-25T15:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62939#M12608</link>
      <description>&lt;P&gt;BTW, on my forwarders, using tcpdump, I never see port 8089 used. I do see the forwarder listening on port 8089, just no data flowing. Seems odd. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 15:35:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62939#M12608</guid>
      <dc:creator>hokie1999</dc:creator>
      <dc:date>2013-02-25T15:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62940#M12609</link>
      <description>&lt;P&gt;The communication on port 8089 will only be if you've setup the deployment server.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 15:48:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62940#M12609</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2013-02-25T15:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62941#M12610</link>
      <description>&lt;P&gt;Splunk will only use src port 9997 as replies (src ports are usually higher numbers).  I suspect you're reading this data incorrectly.  Unless you've set your indexers to output data to the forwarders, there's no reason for the indexers to initiate communication.  If they were, the src ports would be higher random numbered ports.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 15:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62941#M12610</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2013-02-25T15:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62942#M12611</link>
      <description>&lt;P&gt;you can add :&lt;BR /&gt;
port 8089 for the license-master (from license-slave to license-master)&lt;BR /&gt;
port XXXX for the replication cluster master, and slaves.&lt;/P&gt;

&lt;P&gt;and any other ports open to monitor tcp/udp.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 15:59:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62942#M12611</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-02-25T15:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62943#M12612</link>
      <description>&lt;P&gt;From splunk indexer 1: &lt;/P&gt;

&lt;P&gt;tcpdump src port 9997&lt;/P&gt;

&lt;P&gt;16:03:15.882512 IP ddcsplunkindex01.ddc.verizon.com.palace-6 &amp;gt; 152.190.138.xxx.40612: Flags [P.], seq 114:171, ack 3058, win 6767, options [nop,nop,TS val 511776904 ecr 342512613], length 57&lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2013 16:07:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62943#M12612</guid>
      <dc:creator>hokie1999</dc:creator>
      <dc:date>2013-02-25T16:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62944#M12613</link>
      <description>&lt;P&gt;This is a diagram of Splunk components and network ports that are commonly used in a Splunk Enterprise environment. Firewall rules often need to be updated to allow communication on ports 8000, 8089, 9997, 514 and others.&lt;/P&gt;

&lt;P&gt;Source files available here: &lt;A href="http://downloads.jordan2000.com/splunk/"&gt;http://downloads.jordan2000.com/splunk/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Updated version&lt;BR /&gt;
&lt;IMG src="http://downloads.jordan2000.com/splunk/Splunk-Common-Network-Ports-v2.0.3.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Original version&lt;BR /&gt;
&lt;IMG src="http://downloads.jordan2000.com/splunk/Splunk-Common-Network-Ports-ver1.6.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 21:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62944#M12613</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2014-01-15T21:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62945#M12614</link>
      <description>&lt;P&gt;clap clap clap.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2014 22:07:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62945#M12614</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2014-01-15T22:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62946#M12615</link>
      <description>&lt;P&gt;9997 is not a default; just a convention.  You need to set it explicitly on the receiving instance (indexer).&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 19:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62946#M12615</guid>
      <dc:creator>Steve_G_</dc:creator>
      <dc:date>2014-11-10T19:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62947#M12616</link>
      <description>&lt;P&gt;It seems many are confused about port required from UFs to a HF. Which is 9997 too i.e.&lt;/P&gt;

&lt;P&gt;UFs ---9997---&amp;gt; HF --- 9997---&amp;gt; Indexers&lt;BR /&gt;
UFs, Indexers, SHs ---8089 ---&amp;gt; DS &lt;/P&gt;

&lt;P&gt;Many uses HF &amp;amp; DS as same server.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2014 01:15:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62947#M12616</guid>
      <dc:creator>nitinsheenu</dc:creator>
      <dc:date>2014-11-25T01:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62948#M12617</link>
      <description>&lt;P&gt;Wow. Nicely done. This is so hard to find in the official documentation.&lt;/P&gt;

&lt;P&gt;I would also suggest adding flows on port 9997 from the search heads, deployment server, license server, and cluster master to the indexers, with a footnote that this is an optional flow used for forwarding Splunk's internal indexes (a recommended best practice).&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 02:14:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62948#M12617</guid>
      <dc:creator>steven_swor</dc:creator>
      <dc:date>2015-02-03T02:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62949#M12618</link>
      <description>&lt;P&gt;Since splunk 6.2 also port 8191 is used for the kvstore.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2015 09:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62949#M12618</guid>
      <dc:creator>renems</dc:creator>
      <dc:date>2015-02-26T09:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62950#M12619</link>
      <description>&lt;P&gt;Kudos.  This is very helpful Rob.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2015 14:26:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62950#M12619</guid>
      <dc:creator>tross33</dc:creator>
      <dc:date>2015-03-09T14:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62951#M12620</link>
      <description>&lt;P&gt;I should get around to updating soon with the feedback I've received.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 20:36:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62951#M12620</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2015-03-24T20:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62952#M12621</link>
      <description>&lt;P&gt;And mark which connections are using SSL bei default (which have to be switched on manually...)&lt;/P&gt;

&lt;P&gt;Great picture!&lt;/P&gt;

&lt;P&gt;Thank you very much...&lt;/P&gt;

&lt;P&gt;Holger&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 16:07:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62952#M12621</guid>
      <dc:creator>hsesterhenn_spl</dc:creator>
      <dc:date>2015-04-20T16:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: What are the ports that I need to open?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62953#M12622</link>
      <description>&lt;P&gt;@rob_jordan : Your picture speaks 100000k words &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  very helpful&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2015 15:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-ports-that-I-need-to-open/m-p/62953#M12622</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2015-06-02T15:03:31Z</dc:date>
    </item>
  </channel>
</rss>

