<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What ports does a forwarder bind to for sending data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-ports-does-a-forwarder-bind-to-for-sending-data/m-p/73860#M15123</link>
    <description>&lt;P&gt;'randomly' is a little unfair.  The OS will choose an ephemeral port number and use that.  How the OS determines the ephemeral port is OS dependent and also is related to how many ephemeral ports have been used so far.  On Linux the ephemeral port range is controlled by the sysctl net.ipv4.ip_local_port_range, and on Windows it's a registry setting.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:19:27 GMT</pubDate>
    <dc:creator>dwaddle</dc:creator>
    <dc:date>2020-09-28T09:19:27Z</dc:date>
    <item>
      <title>What ports does a forwarder bind to for sending data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-ports-does-a-forwarder-bind-to-for-sending-data/m-p/73858#M15121</link>
      <description>&lt;P&gt;I'm trying to determine the port range that a forwarder uses as it's source port. Assuming I'm reading $SPLUNK_HOME/var/log/splunk/metrics.log correctly, I'm seeing data sourced from ports in the 30,000 and 50,000 range.&lt;/P&gt;

&lt;P&gt;Is this something I can specify when configuring a forwarder?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 22:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-ports-does-a-forwarder-bind-to-for-sending-data/m-p/73858#M15121</guid>
      <dc:creator>CarlS</dc:creator>
      <dc:date>2010-10-20T22:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: What ports does a forwarder bind to for sending data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-ports-does-a-forwarder-bind-to-for-sending-data/m-p/73859#M15122</link>
      <description>&lt;P&gt;I do not believe you can configure the port setting for the port range that a forwarder uses as it's source.  If I recall correctly, this is randomly determined by the OS.   &lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 22:39:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-ports-does-a-forwarder-bind-to-for-sending-data/m-p/73859#M15122</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-10-20T22:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: What ports does a forwarder bind to for sending data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-ports-does-a-forwarder-bind-to-for-sending-data/m-p/73860#M15123</link>
      <description>&lt;P&gt;'randomly' is a little unfair.  The OS will choose an ephemeral port number and use that.  How the OS determines the ephemeral port is OS dependent and also is related to how many ephemeral ports have been used so far.  On Linux the ephemeral port range is controlled by the sysctl net.ipv4.ip_local_port_range, and on Windows it's a registry setting.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:19:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-ports-does-a-forwarder-bind-to-for-sending-data/m-p/73860#M15123</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2020-09-28T09:19:27Z</dc:date>
    </item>
  </channel>
</rss>

