Getting Data In

What does splunk-parameter "--auto-ports"do?

rvany
Communicator

This parameter is used in auto-install-scripts for the Universal Forwarder but I could not find any information about it in the documentation. Is this something used in older versions of Splunk?

The Linux-strings-command outputs "--auto-ports" in /opt/splunk/bin/splunk - so it is recognized (like e.g. --accept-license).

1 Solution

lguinn2
Legend

I believe that the auto-ports option still works in the latest version (6.6) of Splunk. What it does:

Splunk begins with the default port number for splunkd (8089 unless you have also changed the default). If that port is available, Splunk uses it for splunkd. However, if the port is not available, Splunk automatically increments the port and tries again (8090, 8091, etc.). It uses the first available port number that it finds.

This option is often used when installing the Universal Forwarder because we usually don't care which port is assigned to splunkd.

View solution in original post

lguinn2
Legend

I believe that the auto-ports option still works in the latest version (6.6) of Splunk. What it does:

Splunk begins with the default port number for splunkd (8089 unless you have also changed the default). If that port is available, Splunk uses it for splunkd. However, if the port is not available, Splunk automatically increments the port and tries again (8090, 8091, etc.). It uses the first available port number that it finds.

This option is often used when installing the Universal Forwarder because we usually don't care which port is assigned to splunkd.

rvany
Communicator

One additional question:

In the universal forwarder installation script this parameter is used in conjunction with "splunk set deploy-poll". Does this make sense? I would say this port is fixed/given by the configuration of the deployment-server.

0 Karma

lguinn2
Legend

No - the port given for the deployment server is the deployment server's management port. This is completely unrelated to auto-ports or the forwarder's own management port.

0 Karma

rvany
Communicator

Thank you. I added some feedback to the respective documentation so this information could be added there.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Thanks for that feedback. We'll get the documentation updated with this information shortly.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

March Community Office Hours Security Series Uncovered!

Hello Splunk Community! In March, Splunk Community Office Hours spotlighted our fabulous Splunk Threat ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars in April. This post ...