Deployment Architecture

How to create custom network port?

sanjubaba
Path Finder

How to create custom network port to receive data on Splunk syslog server ? I don't want data to be received on default port.

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

are you speaking of receiving logs from Forwarders or syslogs?

if Forwarders, go in [Settings -- Forwardering and Receiving -- Configure Receiving[ on Indexers and choose the port you like (9997 is the default).

If syslogs, choose the port in the inputs configuration [Settings -- Data Inputs -- TCP/UDP -- New Local TCP/UDP], (514 is the default).

Ciao.

Giuseppe

0 Karma

sanjubaba
Path Finder

@gcusello I want logs on syslog server(which is the forwarder machine) from network devices.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

let me understand:

you have an Heavy Forwarder that has to receive syslogs, is this correct?

If this is your need, you have to go in the network inputs and set the port you want.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...