I am trying to connect a Universal Forwarder on a Windows 10 computer to Splunk on another Windows 10 computer.
Is port 9997 the only port which must be opened on the firewall. Is the port TCP?
9997 to each indexer and 8089 to the deployment server, if used - all TCP.
Hi @rayeverestnature,
Splunk uses port 9997 between a UF/HF and indexer . Please refer here to have a comprehensive network port diagram
https://docs.splunk.com/Documentation/Splunk/7.1.1/InheritedDeployment/Ports
And port 8089 to the deployment server.