All Apps and Add-ons

Splunk Stream Confusion

newportknight
Loves-to-Learn

Hi,

I'm trying to install Splunk Stream in a distributed environment but the more I read the more confused I'm getting and less I understand!

I have a distribution server deploying the Stream_TA_stream app to a universal forwarder on a Windows 10 PC (10.1.1.1) and this looks to be successful as I'm seeing the app along with my inputs.conf. Within my inputs.conf I have the splunk_stream_app_location set as http://10.1.1.11:8000/en-us/custom/splunk_app_stream/ 

10.1.1.11 is my Splunk Stream server with splunk_app_stream and splunk_TA_stream_wire_data installed. Under the Stream App config I have created a test stream looking for ICMP and under Distributed Forwarder Management a group with HEC off and an endpoint URL http://10.1.1.1.windows.uf:8088 

In Matched Forwarders should I be seeing my Win10 PC 10.1.1.1 in the Preview of matched Forwarders?

I have used Wireshark and can see comms on tcp port 8000 including the http 'ping' and an http 200 OK response but no other communications on any other port. Can anyone shed some light on what should happen next and how the Stream config is ‘shared’?

Any help/advise would be greatly appreciated.

Cheers.

Paul.

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...