I am very new with Splunk. I started lerning it with on line courses.
I need to configure Forwarding in heavy forwarder.
Here are the steps: Configure Forwarding -- Forward Data -- New Forwarding Host: insert hostname:port or IP:port
But I do not know how to find the IP:port
Can anyone help me?
Is this search head running on-perm? Do you have access to the search head's CLI? If it is *Nix, do a
ifconfig
at command line and it should give you the IP address. The default port for receiving data is 9997. You can find the exact port under "Settings" --> "Forwarding and Receiving" if the default is not used.