All Apps and Add-ons

Error with Splunk Stream: Unable to initialize modular input "streamfwd" defined inside the app "Splunk_TA_stream"

akshatj2
Path Finder

Hi All,

We are receiving below error in Splunk Stream App

we have installed a separate Universal forwarder and installed the Stream Add-on on it to read PCAP files. Any help on the same would be helpful.

Unable to initialize modular input "streamfwd" defined inside the app "Splunk_TA_stream": Introspecting scheme=streamfwd: script running failed (exited with code 1).

0 Karma

iandrews_splunk
Splunk Employee
Splunk Employee

Stream doesn't support universal forwarders. You'll have to install it on a Heavy Forwarder (Splunk Enterprise, configured like a forwarder)

Also, make sure you follow the setup instructions (http://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/InstallSplunkAppforStream)

0 Karma

ehudb
Contributor

According to the official guide, it does support universal forwarder:

https://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/InstallSplunkAppforStream#Manu...

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...