Deployment Architecture

adding local port inside HF to accept data

KhalidAlharthi
Explorer

Hello Members,

 

I have configured splunk HF to recieve data input as port 1531/udp 

 

i used command firewall-cmd --permanent --zone=public --add-port=1531/udp

 

but when i used firewall-cmd --list-all dosen't appear on the opening ports is this consider a problem and also checked netstat and the port is listening on 0.0.0.0 (all)

 

thanks

Labels (1)
0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@KhalidAlharthi 

1. Reload Firewall Rules : sudo firewall-cmd --reload

2. Verify the Rule is Active: sudo firewall-cmd --list-all

3. Consider SELinux: If you're using SELinux (Security-Enhanced Linux), it could also be blocking access. You can temporarily disable it to test if that's the issue : 
sudo setenforce 0

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

PickleRick
SplunkTrust
SplunkTrust

SELinux has nothing to do with firewalld in the sense that adding a rule to firewalld should work regardless of SELinux status - the rule should show. True, SELinux coud prevent the process from processing connection but that's completely independent from firewalld.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...