<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: streamfwd app error in /var/log/splunk/streamfwd.log in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/658837#M27502</link>
    <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;I have this problem last week and this error occur&lt;/P&gt;&lt;P&gt;i searched in any communities but i didn't find any solution&lt;/P&gt;&lt;P&gt;i'm using ubuntu 64 bit&lt;/P&gt;&lt;P&gt;i checked both interface that connect to my forwarder. both of them had this problem and error&lt;/P&gt;&lt;P&gt;please help us if every one have solution&lt;/P&gt;</description>
    <pubDate>Wed, 27 Sep 2023 09:12:19 GMT</pubDate>
    <dc:creator>milad001mehdi</dc:creator>
    <dc:date>2023-09-27T09:12:19Z</dc:date>
    <item>
      <title>streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/658283#M27465</link>
      <description>&lt;P&gt;Hello! I am trying to get the streamfwd app to capture traffic on an interface located on my virtual machine.&lt;/P&gt;&lt;P&gt;Does this app not recognize link layer virtualization? This is the error I am receiving and currently can't find a workaround...&lt;/P&gt;&lt;P&gt;"(SnifferReactor/PcapNetworkCapture.cpp:238)&amp;nbsp; stream.NetworkCapture - SnifferReactor unrecognized link layer for device &amp;lt;lo0&amp;gt;: 253"&lt;/P&gt;&lt;P&gt;I was also receiving the same error when I changed my streamfwd.conf to capture on a different network interface. Even tried putting the interface into promiscuous mode. Any help/troubleshooting on this would be appreciated! Fysa, I am using a 64bit CentOS8.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 13:33:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/658283#M27465</guid>
      <dc:creator>johnncennaa</dc:creator>
      <dc:date>2023-09-21T13:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/658837#M27502</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;I have this problem last week and this error occur&lt;/P&gt;&lt;P&gt;i searched in any communities but i didn't find any solution&lt;/P&gt;&lt;P&gt;i'm using ubuntu 64 bit&lt;/P&gt;&lt;P&gt;i checked both interface that connect to my forwarder. both of them had this problem and error&lt;/P&gt;&lt;P&gt;please help us if every one have solution&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 09:12:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/658837#M27502</guid>
      <dc:creator>milad001mehdi</dc:creator>
      <dc:date>2023-09-27T09:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/675281#M27877</link>
      <description>&lt;P&gt;I'm have the same problem.&amp;nbsp; Multiple VMs with Stream that have been working, but they all now fail with "unrecognized link layer for this device &amp;lt;eth1&amp;gt; 253".&amp;nbsp; &amp;nbsp;Does the current version no longer support link layer virtualization&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 15:34:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/675281#M27877</guid>
      <dc:creator>jratl2t</dc:creator>
      <dc:date>2024-01-24T15:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/675366#M27880</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the same problem too, on my ubuntu VM with the interface ens33. If you find the solution, ping me please.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 11:12:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/675366#M27880</guid>
      <dc:creator>adrojis</dc:creator>
      <dc:date>2024-01-25T11:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/680060#M27965</link>
      <description>&lt;P&gt;Hi Splunkers&lt;/P&gt;&lt;P&gt;I notice the same issue and wonder really why Splunk is not fixing this issue?&lt;BR /&gt;Is seems to be an incompatibility on the &lt;STRONG&gt;VMware stack&lt;/STRONG&gt; with the &lt;STRONG&gt;streamfwd&lt;/STRONG&gt; service.&amp;nbsp;&lt;BR /&gt;I use Splunk Universalforwarder 9.1.2 and Splunk Stream 9.1.1.&lt;/P&gt;&lt;P&gt;Specially the installation on Universalforwarders fails massively on Linux systems which makes Splunk Stream not really usable in a distributed environment with Linux systems.&lt;BR /&gt;&lt;BR /&gt;My &lt;STRONG&gt;streamfwd.log&lt;/STRONG&gt; tells always the same error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2024-03-08 14:59:54 INFO  [139974317471680] (CaptureServer.cpp:2001) stream.CaptureServer - Starting data capture
2024-03-08 14:59:54 INFO  [139974317471680] (SnifferReactor/SnifferReactor.cpp:161) stream.SnifferReactor - Starting network capture: sniffer
2024-03-08 14:59:54 ERROR [139974317471680] (SnifferReactor/PcapNetworkCapture.cpp:238) stream.NetworkCapture - SnifferReactor unrecognized link layer for device &amp;lt;eth0&amp;gt;: 253
2024-03-08 14:59:54 FATAL [139974317471680] (CaptureServer.cpp:2337) stream.CaptureServer - SnifferReactor was unable to start packet capturesniffer
2024-03-08 14:59:54 INFO  [139974317471680] (CaptureServer.cpp:2362) stream.CaptureServer - Done pinging stream senders (config was updated)
2024-03-08 14:59:54 INFO  [139974317471680] (main.cpp:1109) stream.main - streamfwd has started successfully (version 8.1.1 build afdcef4b)
2024-03-08 14:59:54 INFO  [139974317471680] (main.cpp:1111) stream.main - web interface listening on port 8889&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As you all can see, my &lt;STRONG&gt;streamfwd.conf&lt;/STRONG&gt; is more or less the same as all of you have also.&lt;BR /&gt;No matter if for example i change the &lt;STRONG&gt;ipAddr&lt;/STRONG&gt; to &lt;STRONG&gt;0.0.0.0. &lt;/STRONG&gt;I always get the same error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[streamfwd]
logConfig = streamfwdlog.conf
port = 8889
ipAddr = 127.0.0.1
## --&amp;gt; Token HFWD
httpEventCollectorToken = ba4a2b2-2544-55e3-22ft-234vt68m0szp
## --&amp;gt; Specify the interface
streamfwdcapture.1.interface = eth0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Side remark:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;If I reinstall &lt;STRONG&gt;Splunk Enterprise&lt;/STRONG&gt; &lt;STRONG&gt;9.1.2&lt;/STRONG&gt; on the same server on which &lt;STRONG&gt;UniversalForwarder 9.1.2&lt;/STRONG&gt; with &lt;STRONG&gt;Splunk Stream 9.1.1&lt;/STRONG&gt; was installed, Splunk Stream works.&lt;BR /&gt;That sounds like a bug in &lt;EM&gt;Splunk_TA_stream&lt;/EM&gt;.&lt;BR /&gt;&lt;BR /&gt;Would be great to hear a statement of Splunk within the next weeks.&lt;BR /&gt;Kind regards&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 14:27:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/680060#M27965</guid>
      <dc:creator>patrickvanreck</dc:creator>
      <dc:date>2024-03-08T14:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/680062#M27966</link>
      <description>&lt;P&gt;We finally got stream working - but more of a work around.&amp;nbsp; The problem is in part due to starting the UF using systemd, which allocates CPU slices for different processes.&amp;nbsp; &amp;nbsp;When using systemd to start the UF, stream fails.&amp;nbsp; &amp;nbsp;Disabling start on boot, and manually starting the UF from ./slunk start, stream works.&lt;BR /&gt;&lt;BR /&gt;The second part is that when the UF starts, ownership of all the UF files is chowned&amp;nbsp; splunk:splunk.&amp;nbsp; This seems logical to ensure the UF runs as splunk (or splunkfwd).&amp;nbsp; However, when stream is initially installed, the set_permissions.sh changes ownership of ../Splunk_TA_stream/Linux_x86_64/streamfwd-rhel6 to root.&amp;nbsp; Starting the UF undoes this, changing ownership back to splunk.&amp;nbsp; &amp;nbsp;We made streamfwwd-rhel6 immutable - which did prevent the ownership change back to splunk, but stream still failed when starting with systemd.&lt;BR /&gt;&lt;BR /&gt;Ultimately, we had to disable systemd, make streamfwd-rhel6 immutable (after running set_permissions.sh), then start the UF manually via /splunk start.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Splunk needs to fix this so stream works as expected without having to disable boot-start and set the immutable flag.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 14:41:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/680062#M27966</guid>
      <dc:creator>jorob</dc:creator>
      <dc:date>2024-03-08T14:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/698282#M28522</link>
      <description>&lt;P&gt;Hi Jorob&lt;/P&gt;&lt;P&gt;I saw this option as well. But what if we don't want to run the Splunk daemon in &lt;STRONG&gt;/etc/init.d&lt;/STRONG&gt;?&lt;BR /&gt;I mean, the problem should be well known by Splunk and since allmost a year we don't hear any improvements from them.&lt;/P&gt;&lt;P&gt;I'm a little disappointed on Splunk's part that they don't describe a workaround in the docs or even look for the solution.&amp;nbsp;It looks like nobody at Splunk cares about this problem.&lt;/P&gt;&lt;P&gt;As I mentioned, I think it's a bad idea to have to install all universal forwarders in the “old” way just because Splunk Stream can't handle it.&lt;/P&gt;&lt;P&gt;We are all eagerly awaiting Splunk's response.&lt;/P&gt;&lt;P&gt;Greetings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 11:01:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/698282#M28522</guid>
      <dc:creator>patrickvanreck</dc:creator>
      <dc:date>2024-09-05T11:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/701820#M28705</link>
      <description>&lt;DIV class=""&gt;Edit Splunk systemd service unit file and edit/add the line under [service]&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;AmbientCapabilities=CAP_DAC_READ_SEARCH CAP_NET_ADMIN CAP_NET_RAW​&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 14:19:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/701820#M28705</guid>
      <dc:creator>seanatrons</dc:creator>
      <dc:date>2024-10-14T14:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: streamfwd app error in /var/log/splunk/streamfwd.log</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/701827#M28708</link>
      <description>&lt;P&gt;Can you explain more?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which file should be edit?&lt;/P&gt;&lt;P&gt;Send path and file name&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 15:32:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/streamfwd-app-error-in-var-log-splunk-streamfwd-log/m-p/701827#M28708</guid>
      <dc:creator>milad001mehdi</dc:creator>
      <dc:date>2024-10-14T15:32:20Z</dc:date>
    </item>
  </channel>
</rss>

