How to create custom network port to receive data on Splunk syslog server ? I don't want data to be received on default port.
Hi @sanjubaba,
are you speaking of receiving logs from Forwarders or syslogs?
if Forwarders, go in [Settings -- Forwardering and Receiving -- Configure Receiving[ on Indexers and choose the port you like (9997 is the default).
If syslogs, choose the port in the inputs configuration [Settings -- Data Inputs -- TCP/UDP -- New Local TCP/UDP], (514 is the default).
Ciao.
Giuseppe
@gcusello I want logs on syslog server(which is the forwarder machine) from network devices.
Hi @sanjubaba,
let me understand:
you have an Heavy Forwarder that has to receive syslogs, is this correct?
If this is your need, you have to go in the network inputs and set the port you want.
Ciao.
Giuseppe