Getting Data In

What does splunk-parameter "--auto-ports"do?

rvany
Communicator

This parameter is used in auto-install-scripts for the Universal Forwarder but I could not find any information about it in the documentation. Is this something used in older versions of Splunk?

The Linux-strings-command outputs "--auto-ports" in /opt/splunk/bin/splunk - so it is recognized (like e.g. --accept-license).

1 Solution

lguinn2
Legend

I believe that the auto-ports option still works in the latest version (6.6) of Splunk. What it does:

Splunk begins with the default port number for splunkd (8089 unless you have also changed the default). If that port is available, Splunk uses it for splunkd. However, if the port is not available, Splunk automatically increments the port and tries again (8090, 8091, etc.). It uses the first available port number that it finds.

This option is often used when installing the Universal Forwarder because we usually don't care which port is assigned to splunkd.

View solution in original post

lguinn2
Legend

I believe that the auto-ports option still works in the latest version (6.6) of Splunk. What it does:

Splunk begins with the default port number for splunkd (8089 unless you have also changed the default). If that port is available, Splunk uses it for splunkd. However, if the port is not available, Splunk automatically increments the port and tries again (8090, 8091, etc.). It uses the first available port number that it finds.

This option is often used when installing the Universal Forwarder because we usually don't care which port is assigned to splunkd.

rvany
Communicator

One additional question:

In the universal forwarder installation script this parameter is used in conjunction with "splunk set deploy-poll". Does this make sense? I would say this port is fixed/given by the configuration of the deployment-server.

0 Karma

lguinn2
Legend

No - the port given for the deployment server is the deployment server's management port. This is completely unrelated to auto-ports or the forwarder's own management port.

0 Karma

rvany
Communicator

Thank you. I added some feedback to the respective documentation so this information could be added there.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Thanks for that feedback. We'll get the documentation updated with this information shortly.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...