Getting Data In
Highlighted

What are the ports that I need to open?

Engager

Hi for splunk to work properly, what are the ports that I need to open?

Can anyone specify the inbound ports and outbound ports?

Tags (2)
Highlighted

Re: What are the ports that I need to open?

Motivator

defaults are
9997 for forwarders to the Splunk indexer.
8000 for clients to the Splunk Search page
8089 for splunkd (also used by deployment server).

All of these can be changed if desired.

View solution in original post

Highlighted

Re: What are the ports that I need to open?

Splunk Employee
Splunk Employee

9997 is not a default; just a convention. You need to set it explicitly on the receiving instance (indexer).

Highlighted

Re: What are the ports that I need to open?

Engager

Awesome couldn't be more clearer than that.

Highlighted

Re: What are the ports that I need to open?

Splunk Employee
Splunk Employee

I downvoted this post because port listing is at best incomplete and another post better answers the question.

0 Karma
Highlighted

Re: What are the ports that I need to open?

Communicator

KV store port - 8191
Indexer Replication port - 8080
Network port - 514

you may upvoat this now 🙂 @bohanlon @mikelanghorst

Highlighted

Re: What are the ports that I need to open?

Engager

Hi,

I have similar questions, but I need a bit more detail about direction.

Is the splunk forwarder port 9997 tcp/udp from agent to indexer ?
Is the splunk management port 8089 tcp only and from indexer/deployment server to agent or bidirectional?

Cheers

Andy

Highlighted

Re: What are the ports that I need to open?

Motivator

8089 for the deployment server is only needed from the client to the deployment server. Client being indexer, UF, etc.
9997 from the forwarder to the indexer. No connection is needed back from the indexers.
8089 is also used from a Search Head to your indexers. Again only single direction.

Highlighted

Re: What are the ports that I need to open?

Splunk Employee
Splunk Employee

you can add :
port 8089 for the license-master (from license-slave to license-master)
port XXXX for the replication cluster master, and slaves.

and any other ports open to monitor tcp/udp.

0 Karma
Highlighted

Re: What are the ports that I need to open?

Explorer

On my forwarders, I see bi-directional data flowing on port 9997 between the forwarders and the indexers (using tcpdump src port 9997 and tcpdump dst port 9997)

0 Karma