All Apps and Add-ons

How to configure the Stream app on a heavy forwarder and indexer?

khanlarloo
Explorer

Configure stream on a forwarder:

I installed stream app on Splunk HF and indexer, I want to send my routers netflow logs to indexer, I run set_permissions.sh on both of them and configure my streamfwd.conf on HF like this:

[

streamfwd]
logConfig = streamfwdlog.conf
port = 8889

netflowReceiver.0.ip = HF_ip
netflowReceiver.0.port = 9995
netflowReceiver.0.decoder = netflow

And on Indexer

[streamfwd]
logConfig = streamfwdlog.conf
port = 8889

netflowReceiver.0.ip = Indexer_ip
netflowReceiver.0.port = 9995
netflowReceiver.0.decoder = netflow

I configure my routers to send netflow logs to my HF port 9995
but I don't receive any logs from my routers.

Can you tell me what is my problem?

0 Karma

bambarit
Explorer

Hi, did you find the solution? I have same problem

0 Karma

guoqiangchan
New Member

Hi Khanlarloo,

Did you solve your problem ?
I facing the same issue too, any advise ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...