<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder listening on port 8089 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27741#M4661</link>
    <description>&lt;P&gt;I am running across a number vulnerability assessment findings regarding sslv2 being accepted on my SPLUNK Universal forwarder clients.  I am using the Universal Forwarder to send data from my windows and linux machines to my indexer.  I don't need it to listen on any port, that I know of.&lt;/P&gt;

&lt;P&gt;Is it necessary for a universal forwarder to listen on any ports if it is only in use as a client to gather data and forward it to the indexer?  If not, can this be disabled with a deployment app.  Or at least have sslv2 disabled with an app sent to all the clients (I made the server.conf change on the deployment server).  Thanks, as always.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jun 2011 19:53:12 GMT</pubDate>
    <dc:creator>trross33</dc:creator>
    <dc:date>2011-06-14T19:53:12Z</dc:date>
    <item>
      <title>Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27741#M4661</link>
      <description>&lt;P&gt;I am running across a number vulnerability assessment findings regarding sslv2 being accepted on my SPLUNK Universal forwarder clients.  I am using the Universal Forwarder to send data from my windows and linux machines to my indexer.  I don't need it to listen on any port, that I know of.&lt;/P&gt;

&lt;P&gt;Is it necessary for a universal forwarder to listen on any ports if it is only in use as a client to gather data and forward it to the indexer?  If not, can this be disabled with a deployment app.  Or at least have sslv2 disabled with an app sent to all the clients (I made the server.conf change on the deployment server).  Thanks, as always.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2011 19:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27741#M4661</guid>
      <dc:creator>trross33</dc:creator>
      <dc:date>2011-06-14T19:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27742#M4662</link>
      <description>&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/admin/Secureaccesstoyoursplunkserverwithssl#Disable_SSLv2"&gt;http://www.splunk.com/base/Documentation/latest/admin/Secureaccesstoyoursplunkserverwithssl#Disable_SSLv2&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;server.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;disableDefaultPort = [true|false]
* If true, turns off listening on the splunkd management port (8089 by default)
* Default value is 'false'.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 15 Jun 2011 03:04:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27742#M4662</guid>
      <dc:creator>msettipane</dc:creator>
      <dc:date>2011-06-15T03:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27743#M4663</link>
      <description>&lt;P&gt;Thank you.  If anyone follows up on this thread.  The disableDefaultPort = [true|false] setting is documented here:  &lt;A href="http://www.splunk.com/base/Documentation/latest/admin/Serverconf"&gt;http://www.splunk.com/base/Documentation/latest/admin/Serverconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 14:56:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27743#M4663</guid>
      <dc:creator>trross33</dc:creator>
      <dc:date>2011-06-15T14:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27744#M4664</link>
      <description>&lt;P&gt;Can a server.conf configuration be pushed out with the splunk deployment server?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 15:05:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27744#M4664</guid>
      <dc:creator>trross33</dc:creator>
      <dc:date>2011-06-15T15:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27745#M4665</link>
      <description>&lt;P&gt;Yes, a server.conf configuration can be pushed with deployment server.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 15:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27745#M4665</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-06-15T15:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27746#M4666</link>
      <description>&lt;P&gt;In addition to disabling SSLv2, server.conf allows you to specify valid cipherSuite.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 15:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27746#M4666</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-06-15T15:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27747#M4667</link>
      <description>&lt;P&gt;Thanks. I appreciate it.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2011 20:40:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27747#M4667</guid>
      <dc:creator>trross33</dc:creator>
      <dc:date>2011-06-15T20:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27748#M4668</link>
      <description>&lt;P&gt;How do you manage the apps if you disable the deployment server port? 8089 with a properly created and issued certificate should void any vulnerabilities you have...&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 21:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27748#M4668</guid>
      <dc:creator>kapanig</dc:creator>
      <dc:date>2015-01-07T21:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27749#M4669</link>
      <description>&lt;P&gt;The port 8089 is listening on the UF and is used only for REST/CLI communication handling INBOUND requests to the UF instance.&lt;BR /&gt;
Apps that get deployed to a UF (or actually all splunk instances) are done via a PULL method ie: splunk is configured to reach out to the DS and pull down apps that it's assigned, the DS does not PUSH to the instance.&lt;BR /&gt;
So an opened port is not needed for app deployment as long as the UF can reach the DS:8089 it'll get the apps.&lt;/P&gt;

&lt;P&gt;PS: if you disable port 8089 on the DS itself yes, you kill app deployment.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2017 14:28:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27749#M4669</guid>
      <dc:creator>mattlucas719</dc:creator>
      <dc:date>2017-07-11T14:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27750#M4670</link>
      <description>&lt;P&gt;Very Succinct, Thanks. &lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 15:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27750#M4670</guid>
      <dc:creator>teekayx</dc:creator>
      <dc:date>2017-08-22T15:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder listening on port 8089</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27751#M4671</link>
      <description>&lt;P&gt;Add the following to your etc/system/local/server.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[httpServer]
disableDefaultPort = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;,Add the following to your etc/system/local/server.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[httpServer]
disableDefaultPort = true
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Jan 2019 14:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-listening-on-port-8089/m-p/27751#M4671</guid>
      <dc:creator>ericjaystevens</dc:creator>
      <dc:date>2019-01-29T14:58:57Z</dc:date>
    </item>
  </channel>
</rss>

