Deployment Architecture

How to create custom network port?

sanjubaba
Path Finder

How to create custom network port to receive data on Splunk syslog server ? I don't want data to be received on default port.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

are you speaking of receiving logs from Forwarders or syslogs?

if Forwarders, go in [Settings -- Forwardering and Receiving -- Configure Receiving[ on Indexers and choose the port you like (9997 is the default).

If syslogs, choose the port in the inputs configuration [Settings -- Data Inputs -- TCP/UDP -- New Local TCP/UDP], (514 is the default).

Ciao.

Giuseppe

0 Karma

sanjubaba
Path Finder

@gcusello I want logs on syslog server(which is the forwarder machine) from network devices.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

let me understand:

you have an Heavy Forwarder that has to receive syslogs, is this correct?

If this is your need, you have to go in the network inputs and set the port you want.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...