How can I find my Splunk IP adress search head?

New Member

I am very new with Splunk. I started lerning it with on line courses.
I need to configure Forwarding in heavy forwarder.
Here are the steps: Configure Forwarding -- Forward Data -- New Forwarding Host: insert hostname:port or IP:port

But I do not know how to find the IP:port

Can anyone help me?

Tags (1)
0 Karma


Is this search head running on-perm? Do you have access to the search head's CLI? If it is *Nix, do a


at command line and it should give you the IP address. The default port for receiving data is 9997. You can find the exact port under "Settings" --> "Forwarding and Receiving" if the default is not used.