<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk stream in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536738#M455</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229889"&gt;@iherb_0718&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I assume you installed&amp;nbsp;&lt;SPAN&gt;The Splunk App for Stream on Heavy Forwrder to manage Stream configuration on UFs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You should install &amp;nbsp;"The Splunk Add-on for Stream Forwarders (Splunk_TA_stream)" on every client that you want to collect stream data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this reply helps you an upvote is appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jan 2021 19:25:59 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-01-21T19:25:59Z</dc:date>
    <item>
      <title>splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536728#M452</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;I have a few questions related to splunk stream&lt;/P&gt;&lt;P&gt;1) If a windows computer has splunk stream app installed and it has a UF installed, what are some differences in logging activity will I get between the two?&lt;/P&gt;&lt;P&gt;2) Does the splunk stream app get deployed from the deployment server just as the UF does?&lt;/P&gt;&lt;P&gt;3) Does splunk stream log just web traffic?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 18:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536728#M452</guid>
      <dc:creator>iherb_0718</dc:creator>
      <dc:date>2021-01-21T18:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536733#M453</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229889"&gt;@iherb_0718&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You can find all information regarding Stream on Splunk docs below;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/AboutSplunkStream" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/AboutSplunkStream&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Answers to your questions;&lt;/P&gt;&lt;P&gt;1) Splunk Stream App cannot work standalone it should deployed to UF or Splunk Instance. It adds network traffic capture or PCAP ingestion capabilities to Splunk.&lt;/P&gt;&lt;P&gt;2) You can deploy from deployment server.&lt;/P&gt;&lt;P&gt;3) Supported protocols can be found in documentation. &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/ProtocolDetection" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/ProtocolDetection&lt;/A&gt; &amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 18:58:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536733#M453</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-21T18:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536735#M454</link>
      <description>&lt;P&gt;Scelikok, assume I have all the work for splunk stream done on the splunk side.&amp;nbsp; That is I got the splunk stream app deployed to the heavy forwarder.&amp;nbsp; This would still require an app on the client side?&amp;nbsp; The client already has a UF.&amp;nbsp; It wouldn't be just tweaking the UF conf files to get stream?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 19:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536735#M454</guid>
      <dc:creator>iherb_0718</dc:creator>
      <dc:date>2021-01-21T19:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: splunk stream</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536738#M455</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229889"&gt;@iherb_0718&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I assume you installed&amp;nbsp;&lt;SPAN&gt;The Splunk App for Stream on Heavy Forwrder to manage Stream configuration on UFs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You should install &amp;nbsp;"The Splunk Add-on for Stream Forwarders (Splunk_TA_stream)" on every client that you want to collect stream data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this reply helps you an upvote is appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 19:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/splunk-stream/m-p/536738#M455</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-21T19:25:59Z</dc:date>
    </item>
  </channel>
</rss>

