I would like to change the splunk management port from 8089 to some higher port say 9089. What is the best way to do this? Should i use the Splunk CLI or change it using web.conf file? Also I am using a deployment server to manage the UF. Should I change the port on deployment server as well?
Here is the way to change the default splunk forwarder management port:
In "/etc/system/local", add the following file and contents:
mgmtHostPort = 127.0.0.1:9089
and restart splunk.
It will be like this.
Splunk Server OR DS(ANY)->UF(9089)
Otherwise you can change splunkd port via Web UI or by CLI as mentioned in this answer:
NOTE: The way you change Management Port by Web UI has changed:
- Log in as Admin
- Go to Settings
- Go to Server settings
- Look for Management port and change it
- Save your work!