Splunk Search

Splunk Data flow Diagram

allamiro
Path Finder

Can some one guide us or provoide us with the splunk data flow diagram

with all the port number services etc

Tags (3)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...