Splunk Dev

Port number in event field

rs2OOO
New Member

Sorry for a beginners question, but I have been thrown in the deep end with this.

I have an error.log file, in the event part for each entry it shows [time] [error] [pid number] [IP address:Port number] and then some text.

Does the Port number refer to the IP address shown or to the server creating the error log?

Thanks.

Tags (1)
0 Karma

rs2OOO
New Member

Thanks, that's what I expected but had hoped it was showing the internal port number.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There's a 99.9999% chance the port number refers to the IP address.

---
If this reply helps you, Karma would be appreciated.

woodcock
Esteemed Legend

I'd say 100%. That is standard network convention.

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...