All Apps and Add-ons

Splunk App for Stream. deploying onto Windows

realgandy
Explorer

Hi

Pretty new to Splunk and trying to get to grips with deployment of apps.

I have a deployment server running on Linux and am trying to deploy the splunk app for stream out to a windows server, running universal forwarder, to capture wire data on the windows server.

The deployment appears to work as I get the relevant splunk_TA_stream directory created under apps.

I've looked at all the documentation a hundred times and checked all config files and they appear to contain all the right info, yet no wire capture ever happens.

Has anyone actually got this to work, and if so are you able to offer some direction for me?

Many thanks
Gary

Tags (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

You don't mention installing winpcap on the endpoints. Winpcap is the underlying packet sniffer that Splunk App for Stream relies on to actually capture packets. You can't install winpcap through Splunk, so it's got to be deployed manually or via some other Windows-y method, like SCCM.

If you don't have that, please install it, restart everything involved and see if it doesn't help. For what its worth, it's a tiny, fast, and non-invasive install.

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

You don't mention installing winpcap on the endpoints. Winpcap is the underlying packet sniffer that Splunk App for Stream relies on to actually capture packets. You can't install winpcap through Splunk, so it's got to be deployed manually or via some other Windows-y method, like SCCM.

If you don't have that, please install it, restart everything involved and see if it doesn't help. For what its worth, it's a tiny, fast, and non-invasive install.

0 Karma

realgandy
Explorer

Thanks.

That wasn't the only issue though (not seen that pre-req in any document, maybe I just missed it)... The streamfwd logfile location was a bit screwed in the log4j config file. Corrected that in the local version and now all is working.

Many Thanks for your help

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...