<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Stream App and Developer License in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696401#M80971</link>
    <description>&lt;P&gt;Hi Rick - thanks for the reply. I think forwarder management is supported as I have a deployment server running on the same instance - i have created server classes and deployed app's via this so that aspect appears to be working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My plan was to run stream forwarder on the all in 1 instance and deploy the Splunk_TA_Stream app to my UF's. Should this be possible?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2024 15:41:46 GMT</pubDate>
    <dc:creator>nick_currie</dc:creator>
    <dc:date>2024-08-15T15:41:46Z</dc:date>
    <item>
      <title>Splunk Stream App and Developer License</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696399#M80969</link>
      <description>&lt;P&gt;Hi there, i have a small lab at home on which I am running splunk enterprise 9.0.0 build&amp;nbsp;&lt;SPAN&gt;6818ac46f2ec and a developer license. The&amp;nbsp;&lt;A href="https://192.168.1.119:8000/en-US/manager/system/licensing" target="_blank" rel="noopener"&gt;Licensing&lt;/A&gt;&amp;nbsp;»&amp;nbsp;Installed licenses page shows 3 valid licenses with the following information:&lt;/SPAN&gt;&lt;/P&gt;&lt;H3&gt;. Splunk Enterprise Term Non-Production License&lt;/H3&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;creation_time&lt;/TD&gt;&lt;TD&gt;2024-08-11 07:00:00+00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;expiration_time&lt;/TD&gt;&lt;TD&gt;2025-02-11 07:59:59+00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;features&lt;/TD&gt;&lt;TD&gt;&lt;UL&gt;&lt;LI&gt;Acceleration&lt;/LI&gt;&lt;LI&gt;AdvancedSearchCommands&lt;/LI&gt;&lt;LI&gt;AdvancedXML&lt;/LI&gt;&lt;LI&gt;Alerting&lt;/LI&gt;&lt;LI&gt;ArchiveToHdfs&lt;/LI&gt;&lt;LI&gt;Auth&lt;/LI&gt;&lt;LI&gt;ConditionalLicensingEnforcement&lt;/LI&gt;&lt;LI&gt;CustomRoles&lt;/LI&gt;&lt;LI&gt;DeployClient&lt;/LI&gt;&lt;LI&gt;DeployServer&lt;/LI&gt;&lt;LI&gt;FwdData&lt;/LI&gt;&lt;LI&gt;GuestPass&lt;/LI&gt;&lt;LI&gt;KVStore&lt;/LI&gt;&lt;LI&gt;LocalSearch&lt;/LI&gt;&lt;LI&gt;MultifactorAuth&lt;/LI&gt;&lt;LI&gt;NontableLookups&lt;/LI&gt;&lt;LI&gt;RcvData&lt;/LI&gt;&lt;LI&gt;RollingWindowAlerts&lt;/LI&gt;&lt;LI&gt;SAMLAuth&lt;/LI&gt;&lt;LI&gt;ScheduledAlerts&lt;/LI&gt;&lt;LI&gt;ScheduledReports&lt;/LI&gt;&lt;LI&gt;ScheduledSearch&lt;/LI&gt;&lt;LI&gt;ScriptedAuth&lt;/LI&gt;&lt;LI&gt;SigningProcessor&lt;/LI&gt;&lt;LI&gt;SplunkWeb&lt;/LI&gt;&lt;LI&gt;SubgroupId&lt;/LI&gt;&lt;LI&gt;SyslogOutputProcessor&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;is_unlimited&lt;/TD&gt;&lt;TD&gt;False&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;label&lt;/TD&gt;&lt;TD&gt;Splunk Enterprise Term Non-Production License&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;max_violations&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;notes&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;payload&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;quota_bytes&lt;/TD&gt;&lt;TD&gt;53687091200.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;sourcetypes&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;stack_name&lt;/TD&gt;&lt;TD&gt;enterprise&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;status&lt;/TD&gt;&lt;TD&gt;VALID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;type&lt;/TD&gt;&lt;TD&gt;enterprise&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;window_period&lt;/TD&gt;&lt;TD&gt;30&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;Splunk Forwarder&lt;/H3&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;creation_time&lt;/TD&gt;&lt;TD&gt;2010-06-20 07:00:00+00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;expiration_time&lt;/TD&gt;&lt;TD&gt;2038-01-19 03:14:07+00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;features&lt;/TD&gt;&lt;TD&gt;&lt;UL&gt;&lt;LI&gt;Auth&lt;/LI&gt;&lt;LI&gt;DeployClient&lt;/LI&gt;&lt;LI&gt;FwdData&lt;/LI&gt;&lt;LI&gt;RcvData&lt;/LI&gt;&lt;LI&gt;SigningProcessor&lt;/LI&gt;&lt;LI&gt;SplunkWeb&lt;/LI&gt;&lt;LI&gt;SyslogOutputProcessor&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;hash&lt;/TD&gt;&lt;TD&gt;FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;is_unlimited&lt;/TD&gt;&lt;TD&gt;False&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;label&lt;/TD&gt;&lt;TD&gt;Splunk Forwarder&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;max_violations&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;notes&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;payload&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;quota_bytes&lt;/TD&gt;&lt;TD&gt;1048576.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;sourcetypes&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;stack_name&lt;/TD&gt;&lt;TD&gt;forwarder&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;status&lt;/TD&gt;&lt;TD&gt;VALID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;type&lt;/TD&gt;&lt;TD&gt;forwarder&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;window_period&lt;/TD&gt;&lt;TD&gt;30&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;Splunk Free&lt;/H3&gt;&lt;DIV class=""&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;creation_time&lt;/TD&gt;&lt;TD&gt;2010-06-20 07:00:00+00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;expiration_time&lt;/TD&gt;&lt;TD&gt;2038-01-19 03:14:07+00:00&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;features&lt;/TD&gt;&lt;TD&gt;&lt;UL&gt;&lt;LI&gt;FwdData&lt;/LI&gt;&lt;LI&gt;KVStore&lt;/LI&gt;&lt;LI&gt;LocalSearch&lt;/LI&gt;&lt;LI&gt;RcvData&lt;/LI&gt;&lt;LI&gt;ScheduledSearch&lt;/LI&gt;&lt;LI&gt;SigningProcessor&lt;/LI&gt;&lt;LI&gt;SplunkWeb&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;hash&lt;/TD&gt;&lt;TD&gt;FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;is_unlimited&lt;/TD&gt;&lt;TD&gt;False&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;label&lt;/TD&gt;&lt;TD&gt;Splunk Free&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;max_violations&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;notes&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;payload&lt;/TD&gt;&lt;TD&gt;None&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;quota_bytes&lt;/TD&gt;&lt;TD&gt;524288000.0&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;sourcetypes&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;stack_name&lt;/TD&gt;&lt;TD&gt;free&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;status&lt;/TD&gt;&lt;TD&gt;VALID&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;type&lt;/TD&gt;&lt;TD&gt;free&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;window_period&lt;/TD&gt;&lt;TD&gt;30&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to experiment with Splunk Stream for capturing DNS records before implementing in our production environment. I have installed Splunk Stream 8.1.3 and most of the menu's within the app work, however when I go to Configuration &amp;gt; Distributed Forwarder Management it just displays a blank page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When i look at the&amp;nbsp;splunk_app_stream.log I can see the following error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2024-08-15 14:51:58,543 ERROR rest_indexers:62 - failed to get indexers peer&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/splunk/etc/apps/splunk_app_stream/bin/rest_indexers.py", line 55, in handle_GET&lt;BR /&gt;timeout=splunk.rest.SPLUNKD_CONNECTION_TIMEOUT&lt;BR /&gt;File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 612, in simpleRequest&lt;BR /&gt;raise splunk.LicenseRestriction&lt;BR /&gt;splunk.LicenseRestriction: [HTTP 402] Current license does not allow the requested action&lt;BR /&gt;2024-08-15 14:51:58,580 ERROR indexer:52 - failed to list indexers&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/splunk/etc/apps/splunk_app_stream/bin/splunk_app_stream/models/indexer.py", line 43, in get_indexers&lt;BR /&gt;timeout=splunk.rest.SPLUNKD_CONNECTION_TIMEOUT&lt;BR /&gt;File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 669, in simpleRequest&lt;BR /&gt;raise splunk.InternalServerError(None, serverResponse.messages)&lt;BR /&gt;splunk.InternalServerError: [HTTP 500] Splunkd internal error; []&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does this mean that the splunk dev license does not support Splunk Stream app?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 15:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696399#M80969</guid>
      <dc:creator>nick_currie</dc:creator>
      <dc:date>2024-08-15T15:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App and Developer License</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696400#M80970</link>
      <description>&lt;P&gt;It's not about Stream as such. As far as I remember (but I haven't used the Dev license for some time so don't quote me on that), the Dev license alleviate some limitations of the Free license (most importantly lets you have multiple users and schedule searches) but keeps some of them - single instance installation only and no forwarder management as far as I remember.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 15:21:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696400#M80970</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-15T15:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App and Developer License</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696401#M80971</link>
      <description>&lt;P&gt;Hi Rick - thanks for the reply. I think forwarder management is supported as I have a deployment server running on the same instance - i have created server classes and deployed app's via this so that aspect appears to be working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My plan was to run stream forwarder on the all in 1 instance and deploy the Splunk_TA_Stream app to my UF's. Should this be possible?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 15:41:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696401#M80971</guid>
      <dc:creator>nick_currie</dc:creator>
      <dc:date>2024-08-15T15:41:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App and Developer License</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696408#M80972</link>
      <description>&lt;P&gt;You're right. Come to think of it, my Dev licensed box also worked as DS. That's why I said to not quote me on that &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But seriously - the log suggests (you'd have to look in the code d0 verify) that the app is trying to list indexers. And this API endpoint might indeed be not available with Dev license since it's a single instance installation only license.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 17:37:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/696408#M80972</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-15T17:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App and Developer License</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/697931#M81036</link>
      <description>&lt;P&gt;Splunk Stream utilities KVStore Services, 500 ERROR says that App is not able to communicate with KVStore. you can try to make fresh install it will solve this ERRORs and Problem you are facing.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 06:36:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Stream-App-and-Developer-License/m-p/697931#M81036</guid>
      <dc:creator>Meett</dc:creator>
      <dc:date>2024-09-02T06:36:12Z</dc:date>
    </item>
  </channel>
</rss>

