Setup:
Splunk enterprise is on a VM, everything works fine
1 workstation had a universal forwarder
Problem: I need them to talk to eachother on the stream part.
What I have done until now:
When I come to (Splunk VM) - I am lost:
What am I doing wrong?
Install of splunk stream into splunk enterprise (VM) was done with normal config, in other words I haven't changed where apps are installed, so everything is standard there.
I have tried to read: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/ConfigureStreamForwarder
But I'm not getting what I'm doing wrong here.
Any suggestions please? thx
Any suggestions?
Problem solved, I hadn't installed STM (Stream app, just the add on for forwarders)