All Apps and Add-ons

How to configure Splunk Stream on Windows?

z270p
New Member

Hi!

Having some trouble configuring windows to collect data from a Windows forwarder(UF). I have a heavy forwarder configured with token where I also have Splunk_TA_stream installed.
On the search head I have both TA_stream and the actual stream app.
On the Windows forwarder, I have pushed out the TA_stream app with inputs.conf pointing towards the search head. I have also made sure the FW openings have been made so that not an issue.

However can't seem to get a connection to the Windows server. I have it configured on a Linux host which works fine.

Read something about WinPcap. I found the docs a bit confusing here though. Something I need to manually install?

Does anyone have other tips or "good to know" knowledge when it comes to stream and windows forwarder?

Perhaps to get some help I need to specify more info. Let me know in that case!

Thanks!

0 Karma

z270p
New Member

log4cplus.appender.streamfwdlog.File=./streamfwd.log

0 Karma

z270p
New Member

No streamfwd.log seems to have been created I just noticed. On the Windows client-server that is.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...