Splunk Search

Splunk Data flow Diagram

allamiro
Path Finder

Can some one guide us or provoide us with the splunk data flow diagram

with all the port number services etc

Tags (3)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't know that you need a diagram. There isn't that much. Forwarders send to the splunktcp port on the destination (which may be another forwarder, but that is dependent on your designed architecture), which is arbitrary, but conventionally we use 9997. And search heads talk to the splunkd port, which is by default on port 8089.

That's it for data flow. If you need more information, you should probably look at the appropriate sections of the documentation, http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview and http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Aboutindexesandindexers are probably most relevant.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...