All Apps and Add-ons

How to configure Splunk Stream on Windows?

z270p
New Member

Hi!

Having some trouble configuring windows to collect data from a Windows forwarder(UF). I have a heavy forwarder configured with token where I also have Splunk_TA_stream installed.
On the search head I have both TA_stream and the actual stream app.
On the Windows forwarder, I have pushed out the TA_stream app with inputs.conf pointing towards the search head. I have also made sure the FW openings have been made so that not an issue.

However can't seem to get a connection to the Windows server. I have it configured on a Linux host which works fine.

Read something about WinPcap. I found the docs a bit confusing here though. Something I need to manually install?

Does anyone have other tips or "good to know" knowledge when it comes to stream and windows forwarder?

Perhaps to get some help I need to specify more info. Let me know in that case!

Thanks!

0 Karma

z270p
New Member

log4cplus.appender.streamfwdlog.File=./streamfwd.log

0 Karma

z270p
New Member

No streamfwd.log seems to have been created I just noticed. On the Windows client-server that is.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...