For Splunk to run , do firewall service needs to be enabled ?
If i disable the firewall - Is splunk expected to work or not ?
If there is an active firewall in place of any type then it would need to be configured to allow your TCP or UDP traffic through it for the respective ports. If it isn't enabled, then there are no such constraints. Splunk doesn't care...as in your forwarders will attempt to send regardless. Splunk doesn't 'know' about your firewalls unless they are being log monitored as well by an app.
Yes got it.