Getting Data In

What port does the forwarder need opened to the indexers?

williamiamvsi
Engager

Im trying to put in firewall requests for my forwarders. I will need them to communicate back to the indexers to send data, but I don't know what port they use. 8089,8000,8080,9997???

Tags (3)
0 Karma
1 Solution

pwattssplunk
Splunk Employee
Splunk Employee

Forwarder to Indexer communication is done over 9997

View solution in original post

tgow
Splunk Employee
Splunk Employee

Actually 9997 is the default port but you can configure the Forwarder to communicate on any port above 1024.

pwattssplunk
Splunk Employee
Splunk Employee

Forwarder to Indexer communication is done over 9997

patterc
Path Finder

I'd like to add that this answer is half correct. The Indexers RECEIVE data on port 9997, but the Universal Forwarder and Heavy Forwarder SEND the data over a random port.

Within the packet structure, the SRC will be the [ForwarderIP]:[random port] and the DSC will be [Indexer IP]:9997

0 Karma

bmacias84
Champion

I would also open port 8089 from yoru Search Heads or Indexers to UF, HF, or LFs. (Indexer, Search Head, UF, HF, or LF) If you plan on using the CLI. Also this port is required for the (default conf) Deployment Server.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...