Splunk Search

HF multiple UDP port listening | Best practices

GaetanVP
Communicator

Hello Splunkers,

I have a Splunk HF that will receive multiple logs coming from different machines, all sending via UDP.
I am wondering it I need to configures the external sources to send the logs via UDP but with different port (on port for each sources), or if I can simply tell all my sources to send over UDP port 514 for instance.

I am wondering if the UDP port 514 could become a "network bottleneck" because of too many logs coming from multiple sources on the same port. 

Thanks for your help,

GaetanVP

Labels (1)
1 Solution

gcusello
Esteemed Legend

Hi @GaetanVP,

if your data sources permit to configure a different port for each one, it's easier for you because you don't need to manually modify conf files.

But anyway you could also use the same 514 port for all logs and separate data sources based on the ip address, but you need to manually modify conf files because Splunk doesn't permits (via GUI) to add two network data sources using the same port, but it's possible via conf file.

Ciao.

Giuseppe

 

View solution in original post

gcusello
Esteemed Legend

Hi @GaetanVP,

if your data sources permit to configure a different port for each one, it's easier for you because you don't need to manually modify conf files.

But anyway you could also use the same 514 port for all logs and separate data sources based on the ip address, but you need to manually modify conf files because Splunk doesn't permits (via GUI) to add two network data sources using the same port, but it's possible via conf file.

Ciao.

Giuseppe

 

GaetanVP
Communicator

Hello @gcusello,

Thanks a lot for your answer, that makes total sense.

Regards,
GaetanVP

0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...