Hi @human96
On HF please configure below stanza in etc/system/local/inputs.conf
Inputs.conf
[splunktcp:9997]
or using cmd
run follwoing commanf $SPLUNK_HOME/bin/
splunk enable listen 9997 -auth admin:password
Link do doc
https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Enableareceiver