All Apps and Add-ons

Splunk Stream Confusion

newportknight
Loves-to-Learn

Hi,

I'm trying to install Splunk Stream in a distributed environment but the more I read the more confused I'm getting and less I understand!

I have a distribution server deploying the Stream_TA_stream app to a universal forwarder on a Windows 10 PC (10.1.1.1) and this looks to be successful as I'm seeing the app along with my inputs.conf. Within my inputs.conf I have the splunk_stream_app_location set as http://10.1.1.11:8000/en-us/custom/splunk_app_stream/ 

10.1.1.11 is my Splunk Stream server with splunk_app_stream and splunk_TA_stream_wire_data installed. Under the Stream App config I have created a test stream looking for ICMP and under Distributed Forwarder Management a group with HEC off and an endpoint URL http://10.1.1.1.windows.uf:8088 

In Matched Forwarders should I be seeing my Win10 PC 10.1.1.1 in the Preview of matched Forwarders?

I have used Wireshark and can see comms on tcp port 8000 including the http 'ping' and an http 200 OK response but no other communications on any other port. Can anyone shed some light on what should happen next and how the Stream config is ‘shared’?

Any help/advise would be greatly appreciated.

Cheers.

Paul.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...