All Apps and Add-ons

How do I enable splunk stream forwarder? (1 machine, trial version)

Christians86
Explorer
 
 

Setup:

Splunk enterprise is on a VM, everything works fine

1 workstation had a universal forwarder

 

Problem: I need them to talk to eachother on the stream part.

 

What I have done until now:

  • (Splunk VM)I have added the stream app for splunk enterprise and restartet
  • (Workstation)I have added the stream app manually to C:\SplunkUniversalForwarder\etc\apps\Splunk_TA_stream
  • (Workstation)I have added into inputs.conf

    "splunk_stream_app_location =https://192.168.1.115:8000/en-us/custom/splunk_app_stream/"
  • (Workstation)I have not added anything on the workstation to streamfwd

 

When I come to (Splunk VM) - I am lost:

Christians86_0-1628087714037.png

 

What am I doing wrong?

 

Install of splunk stream into splunk enterprise (VM) was done with normal config, in other words I haven't changed where apps are installed, so everything is standard there. 


I have tried to read: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/ConfigureStreamForwarder

 

But I'm not getting what I'm doing wrong here. 

 

Any suggestions please? thx

Labels (3)
0 Karma

Christians86
Explorer
 

Any suggestions?

0 Karma

Christians86
Explorer
 
 

Problem solved, I hadn't installed STM (Stream app, just the add on for forwarders)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...