Port 9997Splunk Indexer Receiving

Splunk indexers use TCP 9997 by default to receive data from forwarders.

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
6/10

risk

lookups
0

rank 994 of 4,021 · top 25%

Technical Details

what runs on :9997

This is Splunk's proprietary forwarder-to-indexer protocol over TCP. A forwarder connects to the configured receiving port and sends event data using Splunk's persistent streaming protocol; the port is configurable, but 9997 is the standard default. TLS can be enabled for the forwarding connection, while Splunk's management interface commonly uses TCP 8089 and HTTP Event Collector commonly uses TCP 8088.

Security Information

exposure of :9997

risk score

6/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

security averages 3.1 across 342 ports — this one sits 2.9 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

This listener should not be exposed directly to the public internet. An exposed receiver can permit unauthorized log or event injection where access controls are insufficient, consume indexer resources, and expose or enable interception of sensitive telemetry if TLS is not configured; restrict sources and enable certificate-based TLS where appropriate.

the 8 most looked-up other ports in security — 342 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted