nerdexam
Splunk

SPLK-2003 · Question #122

Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?

The correct answer is C. SplunkWeb (8000), SplunkD (8089), HTTP Collector (8088). For Splunk SOAR to connect with Splunk Enterprise, certain default ports must be configured to facilitate communication between the two platforms. Typically, SplunkWeb, which serves the Splunk Enterprise web interface, uses port 8000. SplunkD, the Splunk daemon that handles…

Splunk SOAR Environment

Question

Which of the following are the default ports that must be configured on Splunk to allow connections from SOAR?

Options

  • ASplunkWeb (8088), SplunkD (8089), HTTP Collector (8000)
  • BSplunkWeb (8089), SplunkD (8088), HTTP Collector (8000)
  • CSplunkWeb (8000), SplunkD (8089), HTTP Collector (8088)
  • DSplunkWeb (8469), SplunkD (8702), HTTP Collector (8864)

How the community answered

(21 responses)
  • A
    5% (1)
  • C
    90% (19)
  • D
    5% (1)

Explanation

For Splunk SOAR to connect with Splunk Enterprise, certain default ports must be configured to facilitate communication between the two platforms. Typically, SplunkWeb, which serves the Splunk Enterprise web interface, uses port 8000. SplunkD, the Splunk daemon that handles most of the back-end services, listens on port 8089. The HTTP Event Collector (HEC), which allows HTTP clients to send data to Splunk, typically uses port 8088. These ports are essential for the integration, allowing SOAR to send data to Splunk for indexing, searching, and visualization.

Topics

#port configuration#Splunk integration#SplunkWeb#HEC

Community Discussion

No community discussion yet for this question.

Full SPLK-2003 Practice