All Apps and Add-ons

How to configure the Stream app on a heavy forwarder and indexer?

khanlarloo
Explorer

Configure stream on a forwarder:

I installed stream app on Splunk HF and indexer, I want to send my routers netflow logs to indexer, I run set_permissions.sh on both of them and configure my streamfwd.conf on HF like this:

[

streamfwd]
logConfig = streamfwdlog.conf
port = 8889

netflowReceiver.0.ip = HF_ip
netflowReceiver.0.port = 9995
netflowReceiver.0.decoder = netflow

And on Indexer

[streamfwd]
logConfig = streamfwdlog.conf
port = 8889

netflowReceiver.0.ip = Indexer_ip
netflowReceiver.0.port = 9995
netflowReceiver.0.decoder = netflow

I configure my routers to send netflow logs to my HF port 9995
but I don't receive any logs from my routers.

Can you tell me what is my problem?

0 Karma

bambarit
Explorer

Hi, did you find the solution? I have same problem

0 Karma

guoqiangchan
New Member

Hi Khanlarloo,

Did you solve your problem ?
I facing the same issue too, any advise ?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...