Getting Data In

New and started to input data

dxw350
Path Finder

So this is the first time I was trying to input the TCP data port to my monitoring. I am behind a NAT as it is with a FioS router in a home network environment. I wanted to monitor port 80 for web but that is not being allowed (I presume it has to do with the NAT). How do I monitor my computer as a test for traffic going/coming from the web on the Splunk monitoring tool? What settings/port numbers do I need as the input data?

Tags (1)
0 Karma

lguinn2
Legend

Splunk does not care what port you want to monitor - it can be anything. However, Splunk may be restricted because you are running Splunk from a non-privileged account (as you should).

On Linux for example, ports under 1024 are considered privileged; a non- root user cannot read these ports. This may be why you can't monitor port 80. There are ways to get around this.

I am also concerned when you say "monitor port 80 for traffic." Splunk's network inputs (TCP and UDP) read data from the port and index it; is this what you mean by "monitoring"? I feel like this is not what you want. You might also want to look at the free Splunk App for Stream

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...