Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

ports used between splunk instances

$
0
0

I have two splunk instances on either side of a firewall. I use the deployment server and a shared license. Each instance is an indexer and I use distributed search if that matters.

I'm seeing inbound firewall traffic from 8089 to a random high port on the inside of the firewall.

What ports do I need to permit between these two servers? Right now I'm just permitting any tcp between the two but over the last 12 hours, they've made connections on 18 different ports.

How are you guys watching traffic if you have a firewall between the two (in this case it's a firewall between a couple of vlans).

Thanks!

Nick

Snip of ports I'm seeing:

50280 51473 52118 52843 56289 63700 64082 51649 51836 52449 53372 53716 57232 57330 57634 58366 59676 62753


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>