All Apps and Add-ons

Splunk Stream Confusion

newportknight
Loves-to-Learn

Hi,

I'm trying to install Splunk Stream in a distributed environment but the more I read the more confused I'm getting and less I understand!

I have a distribution server deploying the Stream_TA_stream app to a universal forwarder on a Windows 10 PC (10.1.1.1) and this looks to be successful as I'm seeing the app along with my inputs.conf. Within my inputs.conf I have the splunk_stream_app_location set as http://10.1.1.11:8000/en-us/custom/splunk_app_stream/ 

10.1.1.11 is my Splunk Stream server with splunk_app_stream and splunk_TA_stream_wire_data installed. Under the Stream App config I have created a test stream looking for ICMP and under Distributed Forwarder Management a group with HEC off and an endpoint URL http://10.1.1.1.windows.uf:8088 

In Matched Forwarders should I be seeing my Win10 PC 10.1.1.1 in the Preview of matched Forwarders?

I have used Wireshark and can see comms on tcp port 8000 including the http 'ping' and an http 200 OK response but no other communications on any other port. Can anyone shed some light on what should happen next and how the Stream config is ‘shared’?

Any help/advise would be greatly appreciated.

Cheers.

Paul.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...