Splunk Dev

Port number in event field

rs2OOO
New Member

Sorry for a beginners question, but I have been thrown in the deep end with this.

I have an error.log file, in the event part for each entry it shows [time] [error] [pid number] [IP address:Port number] and then some text.

Does the Port number refer to the IP address shown or to the server creating the error log?

Thanks.

Tags (1)
0 Karma

rs2OOO
New Member

Thanks, that's what I expected but had hoped it was showing the internal port number.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There's a 99.9999% chance the port number refers to the IP address.

---
If this reply helps you, Karma would be appreciated.

woodcock
Esteemed Legend

I'd say 100%. That is standard network convention.

0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Announcing the General Availability of Splunk Enterprise Security 8.1!

We are pleased to announce the general availability of Splunk Enterprise Security 8.1. Splunk becomes the only ...

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...