Do you have your Splunk management port open to manage Splunk forwarders. If so what's the risk you are accepting and what compensating controls do you have in place to reduce the risk?
What uses that port?
https://answers.splunk.com/answers/156/what-uses-the-management-port.html
How is it used?
Can you change it? Yes
https://answers.splunk.com/answers/528138/how-to-change-management-port.html
Can you disable it on a forwarder? Yes.
How to disable it using the Deployment Server in a distributed environment?
https://answers.splunk.com/answers/434029/how-to-disable-the-universal-forwarder-default-man.html
Notes about using different ports for certain boxes than others...?
https://answers.splunk.com/answers/543849/different-management-port-for-forwarders-and-index.html
Can you have more than one management port on a single instance? No. There can be only one.
https://answers.splunk.com/answers/594827/using-more-than-one-management-port.html