Monitoring Splunk

Forwarder and indexer communication through port 8089 ?

pgadhari
Builder

Hi All,

Whether port 8089 should be opened bi-directional or uni-directional between forwarder and indexer ? In our setup, there is a firewall between forwarder and indexers, and I need to tell the firewall team about the same. I am asking them to open it bi-directional, but they are not allowing it. They need some Splunk documentation to support this as evidence.

Please clarify the direction and also point me some Splunk document, wherein I can show them as evidence, if bi-directional port opening is required.

Thanks
Pankaj

0 Karma

pgadhari
Builder

I have seen that thread before, but it is not clearly mentioned that whether 8089 should be uni-directional or bi-directional ? Can you tell me which direction is applicable 🙂 ?

Thanks
Pankaj

renems
Communicator

How about this forum question I asked a while ago? Would that count as evidence? 🙂
https://answers.splunk.com/answers/58888/what-are-the-ports-that-i-need-to-open.html#comment-365835

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...