To be more specific, create /opt/splunkforwarder/etc/system/local/web.conf and add:
[settings]
mgmtHostPort = 127.0.0.1:6060
Then, in /opt/splunkforwarder/etc/system/local/server.conf add:
[httpServer]
disableDefaultPort = true
Then restart the forwarder and it should not be listening on any port.
... View more