Deployment Architecture

How to create custom network port?

sanjubaba
Path Finder

How to create custom network port to receive data on Splunk syslog server ? I don't want data to be received on default port.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

are you speaking of receiving logs from Forwarders or syslogs?

if Forwarders, go in [Settings -- Forwardering and Receiving -- Configure Receiving[ on Indexers and choose the port you like (9997 is the default).

If syslogs, choose the port in the inputs configuration [Settings -- Data Inputs -- TCP/UDP -- New Local TCP/UDP], (514 is the default).

Ciao.

Giuseppe

0 Karma

sanjubaba
Path Finder

@gcusello I want logs on syslog server(which is the forwarder machine) from network devices.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

let me understand:

you have an Heavy Forwarder that has to receive syslogs, is this correct?

If this is your need, you have to go in the network inputs and set the port you want.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...