Splunk Search

How can I find my Splunk IP adress search head?

New Member

I am very new with Splunk. I started lerning it with on line courses.
I need to configure Forwarding in heavy forwarder.
Here are the steps: Configure Forwarding -- Forward Data -- New Forwarding Host: insert hostname:port or IP:port

But I do not know how to find the IP:port

Can anyone help me?

Tags (1)
0 Karma


Is this search head running on-perm? Do you have access to the search head's CLI? If it is *Nix, do a


at command line and it should give you the IP address. The default port for receiving data is 9997. You can find the exact port under "Settings" --> "Forwarding and Receiving" if the default is not used.

Get Updates on the Splunk Community!

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...