<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Stream: forwarder configuration in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180893#M17822</link>
    <description>&lt;P&gt;hi. Yes, you can just copy the Splunk_TA_stream from the $SPLUNK_HOME/etc/deployment-apps directory to $SPLUNK_HOME/etc/apps on the forwarder. Splunk_TA_stream contains the streamfwd executable. The Wire Data (streamfwd) modular input in the deployment-apps directory is enabled by default. No need to set up an additional Wire Data input. Make sure to restart splunk after installing Splunk_TA_stream&lt;/P&gt;

&lt;P&gt;For Splunk App for Stream installation instructions, see: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/InstallSplunkAppforStream" target="_blank"&gt;http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/InstallSplunkAppforStream&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For common installation issues, see this troubleshooting item, see:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/Troubleshooting#Splunk_TA_stream_and_Wire_Data_mod_input_not_appearing_after_install" target="_blank"&gt;http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/Troubleshooting#Splunk_TA_stream_and_Wire_Data_mod_input_not_appearing_after_install&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 17:19:41 GMT</pubDate>
    <dc:creator>sroback_splunk</dc:creator>
    <dc:date>2020-09-28T17:19:41Z</dc:date>
    <item>
      <title>Splunk App for Stream: forwarder configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180892#M17821</link>
      <description>&lt;P&gt;We completed the installation of the app and of course, had to manually copy the Splunk_TA_stream to the app/ directory,on the indexer. What wasn't clear to me was what has to be installed on the forwarder? Do we do the same install manually or just copy the Splunk_TA_steam directory structure over to the etc/deployment-apps/ location on the forwarder? It would appear that we need to have the streamfwd executable, and setuid to root at a minimum. Do we then setup a new wire data entry that points to the forwarder?&lt;BR /&gt;
The forwarder setup isn't clear to me yet.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Aug 2014 19:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180892#M17821</guid>
      <dc:creator>goancea</dc:creator>
      <dc:date>2014-08-13T19:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Stream: forwarder configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180893#M17822</link>
      <description>&lt;P&gt;hi. Yes, you can just copy the Splunk_TA_stream from the $SPLUNK_HOME/etc/deployment-apps directory to $SPLUNK_HOME/etc/apps on the forwarder. Splunk_TA_stream contains the streamfwd executable. The Wire Data (streamfwd) modular input in the deployment-apps directory is enabled by default. No need to set up an additional Wire Data input. Make sure to restart splunk after installing Splunk_TA_stream&lt;/P&gt;

&lt;P&gt;For Splunk App for Stream installation instructions, see: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/InstallSplunkAppforStream" target="_blank"&gt;http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/InstallSplunkAppforStream&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For common installation issues, see this troubleshooting item, see:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/Troubleshooting#Splunk_TA_stream_and_Wire_Data_mod_input_not_appearing_after_install" target="_blank"&gt;http://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/Troubleshooting#Splunk_TA_stream_and_Wire_Data_mod_input_not_appearing_after_install&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180893#M17822</guid>
      <dc:creator>sroback_splunk</dc:creator>
      <dc:date>2020-09-28T17:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Stream: forwarder configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180894#M17823</link>
      <description>&lt;P&gt;As sroback_splunk stated, simply copying Splunk_TA_stream/  under the apps/ area worked for me. Since we don't have the executable as setuid root yet, the streamfwd.log file won't be created in the / directory until the perms are updated. Verified by seeing streamfwd info in the splunkd.log file.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2014 14:20:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180894#M17823</guid>
      <dc:creator>goancea</dc:creator>
      <dc:date>2014-08-14T14:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Stream: forwarder configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180895#M17824</link>
      <description>&lt;P&gt;It would be helpful if the documentation were updated to include more detail for installing the stream forwarder.  Also, there is no mention of how to install the Stream App for a distributed deployment of Splunk.  Does the full app get installed on the Search Head and the Indexer?  All the documentation assumes a *nix O.S.  How would the installation change for Windows?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 04:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180895#M17824</guid>
      <dc:creator>greathera</dc:creator>
      <dc:date>2015-07-10T04:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Stream: forwarder configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180896#M17825</link>
      <description>&lt;P&gt;Hi. &lt;/P&gt;

&lt;P&gt;Splunk_TA_stream (aka stream forwarder) is installed with the Splunk app for Stream package. In a distributed environment you can use the deployment server to push the Splunk_TA_stream out to new forwarders or manually install the TA on forwarders. This is covered in the following doc:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/InstallSplunkAppforStream#Splunk_App_for_Stream_components" target="_blank"&gt;http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/InstallSplunkAppforStream#Splunk_App_for_Stream_components&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In a distributed deployment, you must install the Splunk_TA_stream on forwarders and indexers. The Stream app itself only requires installation on search heads. This is covered in the Distributed Deployment section of the Deployment Architectures documentation:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/DeploymentArchitecture" target="_blank"&gt;http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/DeploymentArchitecture&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In terms of Windows installation, the process is identical to Linux/OSX, with the exception that splunkd does not require root privileges on Windows. See Install Splunk App for Stream, Step 3: &lt;A href="http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/InstallSplunkAppforStream#Step_3:_Ensure_Proper_Permissions_.28Linux.2FOSX_only.29" target="_blank"&gt;http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/InstallSplunkAppforStream#Step_3:_Ensure_Proper_Permissions_.28Linux.2FOSX_only.29&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps. &lt;BR /&gt;
Steven&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Stream-forwarder-configuration/m-p/180896#M17825</guid>
      <dc:creator>sroback_splunk</dc:creator>
      <dc:date>2020-09-29T06:38:48Z</dc:date>
    </item>
  </channel>
</rss>

