All Apps and Add-ons

Default port udp/513

timothy_e_rabor
Explorer

Is port udp/513 an absolute or is it just a matter of changing the stanza in the inputs.conf file? I run splunk as a non-root user so I can't configure it to listen on a port < 1024 (I realize too I can play around with some port redirection, but it seems simpler to just change the default port).

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee
[udp:<port>]
* This input stanza is same as [udp://<remote server>:<port>] but without any remote server restriction
* Please see the documentation for [udp://<remote server>:<port>] to follow supported settings:
connection_host = [ip|dns|none]
_rcvbuf = <integer>
no_priority_stripping = [true|false]
no_appending_timestamp = [true|false]
queueSize = <integer>[KB|MB|GB]
persistentQueueSize = <integer>[KB|MB|GB|TB]
listenOnIPv6 = <no | yes | only>
acceptFrom = <network_acl> ...

http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf

0 Karma

timothy_e_rabor
Explorer

The question isn't about inputs.conf. It's about the FortiOS 5 app itself. Documentation refers to using udp/513. I'm asking about using an alternate port for the app. Is changing the inputs.conf file all that is necessary. Will the app still function properly on an alternate port?

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

On Splunk side, it should not matter, but you would need to configure FortiOS to pump logs through the new port.

0 Karma

timothy_e_rabor
Explorer

I'm getting logs no problem. The Fortigate device is set to send logs to one of my heavy forwarders. HF is set to receive properly - logs are being indexed as sourcetype fortios5. That's all working fine.

However, no data is showing in the app itself. The only real deviation I've done is the alternate port. I wouldn't see how that would affect it otherwise if the data is being indexed as the expected sourcetype.

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

If it never worked, I would suggest looking at the app and object permissions.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...