Getting Data In

What port number do deployment servers use to communicate with the forwarder?

kteng2024
Path Finder

Hi,

I can ping Telnet 8089 from forwarder to deployment server, but when I push the app from deployment server, it is not reflected in the forwarder (serverclass is correctly configured). Can I please know:
1. How do you troubleshoot this kind of issue?
2. What port number do deployment servers use to communicate with the forwarder?

0 Karma

woodcock
Esteemed Legend

If you are on the DC and sitting in any directory of the app waiting to see a file change, you never will because the DC will rename the app that you are in, create a new app from the DS and do some merging before deleting the old/renamed app. You have to sit in some other directory and do cat $SPLUNK_HOME/etc/apps/<your app name here>/*/<your conf file here>,conf to test/watch for the change to pull down.

0 Karma

FrankVl
Ultra Champion

Do you see the respective forwarder reporting into the deployment server, when you go to settings -> forwarder management on the web gui of the deployment server?

What does splunkd.log say on the forwarder about its attempts to connect to the deployment server?

If you need further help troubleshooting, please also at least share the relevant part of the serverclass configuration. (maybe best to just open a new question for that)

0 Karma

woodcock
Esteemed Legend

None. The DS does not initiate communication with DCs; it is always the other way around. The default port that DCs use is 8089 but it is not uncommon to change this.

rafamss
Contributor

Hi @kteng2024,

This answer is easily resolved with this other response: https://answers.splunk.com/answers/118859/diagram-of-splunk-common-network-ports.html

[ ]s
RM

0 Karma

lycollicott
Motivator

Port 8089 traffic should be bidirectional, so check that you can telnet to 8089 from the deployment server to the forwarder.

woodcock
Esteemed Legend

You are incorrect. The DS NEVER initiates.

0 Karma

splunk_zen
Builder

I downvoted this post because this is incorrect. a uf does a pull from the ds and doesn't require port 8089 open. the uf 8089 listening admin port can be disabled

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...