Configure Splunk Enterprise to Receive Events

You need to configure Splunk Enterprise to receive events from either the Splunk Universal Forwarder or the Splunk DB Connect application.

For this installation, we assume:

  • Splunk Enterprise is installed
  • Appropriate access to the system is in place
  • You are familiar with the Splunk interface

To configure Splunk Enterprise to receive events:

  1. Click Settings > Forwarding Receiving (under the Data menu).
  2. Click Configure Receiving and then New to create an entry.
  3. Enter 9997 in the Listen on this port field.
  4. Click Save.

Splunk Enterprise is now configured to listen for events sent using any method.