Do you have your Splunk management port open to manage Splunk forwarders. If so what's the risk you are accepting and what compensating controls do you have in place to reduce the risk?
What uses that port?
How is it used?
Can you change it? Yes
Can you disable it on a forwarder? Yes.
How to disable it using the Deployment Server in a distributed environment?
Notes about using different ports for certain boxes than others...?
Can you have more than one management port on a single instance? No. There can be only one.