Splunk Search

Splunk Data flow Diagram

allamiro
Path Finder

Can some one guide us or provoide us with the splunk data flow diagram

with all the port number services etc

Tags (3)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

  Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...