I'm trying to determine the port range that a forwarder uses as it's source port. Assuming I'm reading $SPLUNK_HOME/var/log/splunk/metrics.log correctly, I'm seeing data sourced from ports in the 30,000 and 50,000 range.
Is this something I can specify when configuring a forwarder?
... View more