- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What protocols does the Windows Add on use to collect data and sent it to the Splunk server? HTTPS?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @tmcbride17 ,
let me know if I can help you more, or, please, accept one answer for the other people of Community.
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the quick response!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @tmcbride17 ,
let me know if I can help you more, or, please, accept one answer for the other people of Community.
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @tmcbride17 ,
the correct question is what's the protocol that uses Splunk Universal Forwarder to forward logs to the Indexers?
An add-on is a configuration on the UF.
To send logs, the UF usually uses TCP http or https, it depends if TLS is enabled or not and by default it uses the 9997 port but it can also use HEC, that's less efficient than the other.
Forwarders are managed by the Deployment Server using TCP https on port 8089.
Ciao.
Giuseppe
