Getting Data In

What does splunk-parameter "--auto-ports"do?

rvany
Communicator

This parameter is used in auto-install-scripts for the Universal Forwarder but I could not find any information about it in the documentation. Is this something used in older versions of Splunk?

The Linux-strings-command outputs "--auto-ports" in /opt/splunk/bin/splunk - so it is recognized (like e.g. --accept-license).

1 Solution

lguinn2
Legend

I believe that the auto-ports option still works in the latest version (6.6) of Splunk. What it does:

Splunk begins with the default port number for splunkd (8089 unless you have also changed the default). If that port is available, Splunk uses it for splunkd. However, if the port is not available, Splunk automatically increments the port and tries again (8090, 8091, etc.). It uses the first available port number that it finds.

This option is often used when installing the Universal Forwarder because we usually don't care which port is assigned to splunkd.

View solution in original post

lguinn2
Legend

I believe that the auto-ports option still works in the latest version (6.6) of Splunk. What it does:

Splunk begins with the default port number for splunkd (8089 unless you have also changed the default). If that port is available, Splunk uses it for splunkd. However, if the port is not available, Splunk automatically increments the port and tries again (8090, 8091, etc.). It uses the first available port number that it finds.

This option is often used when installing the Universal Forwarder because we usually don't care which port is assigned to splunkd.

rvany
Communicator

One additional question:

In the universal forwarder installation script this parameter is used in conjunction with "splunk set deploy-poll". Does this make sense? I would say this port is fixed/given by the configuration of the deployment-server.

0 Karma

lguinn2
Legend

No - the port given for the deployment server is the deployment server's management port. This is completely unrelated to auto-ports or the forwarder's own management port.

0 Karma

rvany
Communicator

Thank you. I added some feedback to the respective documentation so this information could be added there.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Thanks for that feedback. We'll get the documentation updated with this information shortly.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...