All Apps and Add-ons

Splunk Stream App and Developer License

nick_currie
Path Finder

Hi there, i have a small lab at home on which I am running splunk enterprise 9.0.0 build 6818ac46f2ec and a developer license. The Licensing » Installed licenses page shows 3 valid licenses with the following information:

. Splunk Enterprise Term Non-Production License

creation_time2024-08-11 07:00:00+00:00
expiration_time2025-02-11 07:59:59+00:00
features
  • Acceleration
  • AdvancedSearchCommands
  • AdvancedXML
  • Alerting
  • ArchiveToHdfs
  • Auth
  • ConditionalLicensingEnforcement
  • CustomRoles
  • DeployClient
  • DeployServer
  • FwdData
  • GuestPass
  • KVStore
  • LocalSearch
  • MultifactorAuth
  • NontableLookups
  • RcvData
  • RollingWindowAlerts
  • SAMLAuth
  • ScheduledAlerts
  • ScheduledReports
  • ScheduledSearch
  • ScriptedAuth
  • SigningProcessor
  • SplunkWeb
  • SubgroupId
  • SyslogOutputProcessor
  
is_unlimitedFalse
labelSplunk Enterprise Term Non-Production License
max_violations5
notesNone
payloadNone
quota_bytes53687091200.0
sourcetypes 
stack_nameenterprise
statusVALID
typeenterprise
window_period30

 

Splunk Forwarder

creation_time2010-06-20 07:00:00+00:00
expiration_time2038-01-19 03:14:07+00:00
features
  • Auth
  • DeployClient
  • FwdData
  • RcvData
  • SigningProcessor
  • SplunkWeb
  • SyslogOutputProcessor
hashFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD
is_unlimitedFalse
labelSplunk Forwarder
max_violations5
notesNone
payloadNone
quota_bytes1048576.0
sourcetypes 
stack_nameforwarder
statusVALID
typeforwarder
window_period30

 

Splunk Free

creation_time2010-06-20 07:00:00+00:00
expiration_time2038-01-19 03:14:07+00:00
features
  • FwdData
  • KVStore
  • LocalSearch
  • RcvData
  • ScheduledSearch
  • SigningProcessor
  • SplunkWeb
hashFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
is_unlimitedFalse
labelSplunk Free
max_violations3
notesNone
payloadNone
quota_bytes524288000.0
sourcetypes 
stack_namefree
statusVALID
typefree
window_period30

 

I would like to experiment with Splunk Stream for capturing DNS records before implementing in our production environment. I have installed Splunk Stream 8.1.3 and most of the menu's within the app work, however when I go to Configuration > Distributed Forwarder Management it just displays a blank page.

When i look at the splunk_app_stream.log I can see the following error

 

2024-08-15 14:51:58,543 ERROR rest_indexers:62 - failed to get indexers peer
Traceback (most recent call last):
File "/opt/splunk/etc/apps/splunk_app_stream/bin/rest_indexers.py", line 55, in handle_GET
timeout=splunk.rest.SPLUNKD_CONNECTION_TIMEOUT
File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 612, in simpleRequest
raise splunk.LicenseRestriction
splunk.LicenseRestriction: [HTTP 402] Current license does not allow the requested action
2024-08-15 14:51:58,580 ERROR indexer:52 - failed to list indexers
Traceback (most recent call last):
File "/opt/splunk/etc/apps/splunk_app_stream/bin/splunk_app_stream/models/indexer.py", line 43, in get_indexers
timeout=splunk.rest.SPLUNKD_CONNECTION_TIMEOUT
File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 669, in simpleRequest
raise splunk.InternalServerError(None, serverResponse.messages)
splunk.InternalServerError: [HTTP 500] Splunkd internal error; []

Does this mean that the splunk dev license does not support Splunk Stream app?

Labels (1)
0 Karma

Meett
Splunk Employee
Splunk Employee

Splunk Stream utilities KVStore Services, 500 ERROR says that App is not able to communicate with KVStore. you can try to make fresh install it will solve this ERRORs and Problem you are facing.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It's not about Stream as such. As far as I remember (but I haven't used the Dev license for some time so don't quote me on that), the Dev license alleviate some limitations of the Free license (most importantly lets you have multiple users and schedule searches) but keeps some of them - single instance installation only and no forwarder management as far as I remember.

0 Karma

nick_currie
Path Finder

Hi Rick - thanks for the reply. I think forwarder management is supported as I have a deployment server running on the same instance - i have created server classes and deployed app's via this so that aspect appears to be working.

 

My plan was to run stream forwarder on the all in 1 instance and deploy the Splunk_TA_Stream app to my UF's. Should this be possible?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

You're right. Come to think of it, my Dev licensed box also worked as DS. That's why I said to not quote me on that 😉

But seriously - the log suggests (you'd have to look in the code d0 verify) that the app is trying to list indexers. And this API endpoint might indeed be not available with Dev license since it's a single instance installation only license.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...