Knowledge Management

New ports open in Splunk 6, how are they utilized?

pkhalsa
New Member

At the "About upgrading to 6.2 - READ THIS FIRST" page, it states:
"This opens two network ports by default on the local machine: 8191 (for KV Store) and 8065 (for Appserver.) "

I want to upgrade my Splunk 5 search head to Splunk 6 today and upgrade all my indexers next week. In the meantime, I wanted to know if the indexers and search head will be communicating on these new ports? I assume so, but this statement isn't so explicit. When it says the ports are opened "on the local machine," it's not clear who the local machine will be communicating with when the new ports are opened.
Thanks.

Tags (2)
0 Karma

malmoore
Splunk Employee
Splunk Employee

The new network ports for Splunk Enterprise 6.2 are open for connections to the local instance. This means that other instances (such as search head cluster members, indexer cluster members, etc.) that use App Key Value Store (port 8191) and Appserver (8065) use these ports to handle those specific operations. If you block those ports, that communication can't happen.

Jrubalcaba
Explorer

Are these ports inbound or outbound?

0 Karma

malmoore
Splunk Employee
Splunk Employee

They are inbound, meaning that the Splunk process listens for connections from other hosts on these ports.

pkhalsa
New Member

Thanks. Will App Key Value Store and Appserver be turned on automatically when I upgrade? Are they essential for Splunk 6 to operate? Otherwise I'm not sure I necessarily need to open up those ports.

0 Karma

malmoore
Splunk Employee
Splunk Employee

Yes, both will be turned on when you upgrade. You should determine whether or not you need to use both features before disabling them. A number of apps use App Key Value a Store, for example.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...