Getting Data In

Why am I unable to add UDP port 162 as a data source?

rgrace110
New Member

When I try to add port 162 UDP I cannot add it. I uninstalled Splunk, rebooted and reinstalled with no luck. Netstat -a shows Splunk listening but I cannot get data as it will not allow me to add the data source. Help please.

Tags (3)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

Are you running as root? You have to be running as root to listen on a port below 1024. See this topic in the Getting Data In manual.

rgrace110
New Member

How can I verify that. The user is a domain admin and should.

0 Karma

rgrace110
New Member

I am doing this simply from the Windows interfaces

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Okay, just to confirm, then: does the user you are running Splunk Enterprise as have access to port 162?

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...