Well, I'm not too familiar with configuring . As for ports, the splunk indexer (receiver) is using the same port all the time, unless you have made an advanced configuration. Most people tend to use port 9997 for log transport. If your indexer is also a Deployment Server, you want to allow traffic from your forwarder to port 8089 (default) on the server.
... View more