Splunk Search

Splunk Data flow Diagram

allamiro
Path Finder

Can some one guide us or provoide us with the splunk data flow diagram

with all the port number services etc

Tags (3)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...