- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is the port that splunk universal forwareder use to sent data to the indexer on a splunk instance, what protocol need to exist between universal forwarder and the splunk instance?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is whatever you set it to. The port in outputs.conf on the forwarder needs to match the port in inputs.conf on the indexer
See the doco
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By default, it's port 9997. Please refer to Splunk Docs to obtain further information on this topic. And remember you can change receiving/admin ports as you please (for example, in case of 2 splunk installations on the same host).
Regards,
Stefano
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is whatever you set it to. The port in outputs.conf on the forwarder needs to match the port in inputs.conf on the indexer
See the doco
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If a port on the system is already used by an application then by definition it is not available to be used by other applications.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to confirm more your answer - Can i use an existing port used and opened?
