<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Used Forwarder Ports in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Used-Forwarder-Ports/m-p/86630#M1951</link>
    <description>&lt;P&gt;That is correct.&lt;/P&gt;

&lt;P&gt;8000 - Web interface&lt;BR /&gt;&lt;BR /&gt;
8089 - Splunkd&lt;BR /&gt;&lt;BR /&gt;
9997 - Receiving port for forwarded events&lt;/P&gt;

&lt;P&gt;You likely won't need to be able to access the Splunkd port from your forwarders unless you're setting up deployment client/servers. Similarly the web interface doesn't have to be accessible from the forwarders. The only port you need to be able to access for that purpose is 9997.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Oct 2011 07:07:55 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2011-10-05T07:07:55Z</dc:date>
    <item>
      <title>Used Forwarder Ports</title>
      <link>https://community.splunk.com/t5/Reporting/Used-Forwarder-Ports/m-p/86629#M1950</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I would like to install a forwarder behind a firewall.&lt;BR /&gt;
It should be a normal forwarder not a lightweight forwarder to collect some data and forward that data to the indexer.&lt;/P&gt;

&lt;P&gt;If I'm right then the only port to open is TCP 9997.&lt;/P&gt;

&lt;P&gt;The other ports splunk uses are &lt;BR /&gt;
web TCP 8000 and management TCP 8089&lt;/P&gt;

&lt;P&gt;Is this right or are there other ports too which splunk use ?&lt;/P&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
Robert&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2011 05:43:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Used-Forwarder-Ports/m-p/86629#M1950</guid>
      <dc:creator>RobertRi</dc:creator>
      <dc:date>2011-10-05T05:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Used Forwarder Ports</title>
      <link>https://community.splunk.com/t5/Reporting/Used-Forwarder-Ports/m-p/86630#M1951</link>
      <description>&lt;P&gt;That is correct.&lt;/P&gt;

&lt;P&gt;8000 - Web interface&lt;BR /&gt;&lt;BR /&gt;
8089 - Splunkd&lt;BR /&gt;&lt;BR /&gt;
9997 - Receiving port for forwarded events&lt;/P&gt;

&lt;P&gt;You likely won't need to be able to access the Splunkd port from your forwarders unless you're setting up deployment client/servers. Similarly the web interface doesn't have to be accessible from the forwarders. The only port you need to be able to access for that purpose is 9997.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2011 07:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Used-Forwarder-Ports/m-p/86630#M1951</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2011-10-05T07:07:55Z</dc:date>
    </item>
  </channel>
</rss>

