How to receive data from forwarders in a Splunk trial/free version instance installed on my personal laptop?
On your laptop Splunk instance, enable listening on a specific port (default 9997) in one of the following ways:
Run this command line in the command console:
splunk enable listen 9997
In Splunk Web, select Settinigs > Forwarding and Receiving from the menu, then click Configure Receiving and add a new listening port - 9997.
Then on your forwarder, run the following command to forward data to your receiving instance and port:
splunk add forward-server <your_laptop_ip>:9997
For more detailed information, please refer to documentation:
Hope this helps. Thanks!
View solution in original post