All Apps and Add-ons

How to configure the Stream app on a heavy forwarder and indexer?

khanlarloo
Explorer

Configure stream on a forwarder:

I installed stream app on Splunk HF and indexer, I want to send my routers netflow logs to indexer, I run set_permissions.sh on both of them and configure my streamfwd.conf on HF like this:

[

streamfwd]
logConfig = streamfwdlog.conf
port = 8889

netflowReceiver.0.ip = HF_ip
netflowReceiver.0.port = 9995
netflowReceiver.0.decoder = netflow

And on Indexer

[streamfwd]
logConfig = streamfwdlog.conf
port = 8889

netflowReceiver.0.ip = Indexer_ip
netflowReceiver.0.port = 9995
netflowReceiver.0.decoder = netflow

I configure my routers to send netflow logs to my HF port 9995
but I don't receive any logs from my routers.

Can you tell me what is my problem?

0 Karma

bambarit
Explorer

Hi, did you find the solution? I have same problem

0 Karma

guoqiangchan
New Member

Hi Khanlarloo,

Did you solve your problem ?
I facing the same issue too, any advise ?

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...