All Apps and Add-ons

Default port udp/513

timothy_e_rabor
Explorer

Is port udp/513 an absolute or is it just a matter of changing the stanza in the inputs.conf file? I run splunk as a non-root user so I can't configure it to listen on a port < 1024 (I realize too I can play around with some port redirection, but it seems simpler to just change the default port).

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee
[udp:<port>]
* This input stanza is same as [udp://<remote server>:<port>] but without any remote server restriction
* Please see the documentation for [udp://<remote server>:<port>] to follow supported settings:
connection_host = [ip|dns|none]
_rcvbuf = <integer>
no_priority_stripping = [true|false]
no_appending_timestamp = [true|false]
queueSize = <integer>[KB|MB|GB]
persistentQueueSize = <integer>[KB|MB|GB|TB]
listenOnIPv6 = <no | yes | only>
acceptFrom = <network_acl> ...

http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf

0 Karma

timothy_e_rabor
Explorer

The question isn't about inputs.conf. It's about the FortiOS 5 app itself. Documentation refers to using udp/513. I'm asking about using an alternate port for the app. Is changing the inputs.conf file all that is necessary. Will the app still function properly on an alternate port?

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

On Splunk side, it should not matter, but you would need to configure FortiOS to pump logs through the new port.

0 Karma

timothy_e_rabor
Explorer

I'm getting logs no problem. The Fortigate device is set to send logs to one of my heavy forwarders. HF is set to receive properly - logs are being indexed as sourcetype fortios5. That's all working fine.

However, no data is showing in the app itself. The only real deviation I've done is the alternate port. I wouldn't see how that would affect it otherwise if the data is being indexed as the expected sourcetype.

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

If it never worked, I would suggest looking at the app and object permissions.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...