All Apps and Add-ons

How to configure a 2nd network interface for Splunk App for Stream?

BG3000
New Member

My Splunk server has two gigabit NICs (eth0 and eth1), both on the same subnet.

eth0 and its assigned IP address is where the main Splunk interface is accessed by other hosts on the subnet (both to access the interface via a web browser, and also to forward log data via syslog or forwarders).

I have connected a SPAN port on my switch to eth1 on my Splunk server. This SPAN port is a mirror of the switch port used by 'Server A' (which is also running the Splunk Universal Forwarder).

I've got the Splunk App for Stream installed and running, but cannot work out how get it to 'listen' on traffic arriving on eth1. In other words, I just want the the Stream app to collect network traffic pertaining to 'Server A' and nothing else. But at present, it seems to be collecting traffic related to the Splunk server itself, which suggests the Stream app is simply 'listening' on eth0.

Please can someone tell me how to configure multiple NICs within Splunk, and also if this is the correct approach to get the Stream App to collect Cisco SPAN port traffic?

Thanks.

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Do you have any explicit network interface configuration set up? You can tell Splunk_TA_stream (the network capture part of Stream) to listen to a specific interface via streamfwd.xml config file - http://docs.splunk.com/Documentation/StreamApp/6.4.2/DeployStreamApp/ConfigureStreamForwarder#Use_Ca...

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...