All Apps and Add-ons

Splunk Stream Confusion

newportknight
Loves-to-Learn

Hi,

I'm trying to install Splunk Stream in a distributed environment but the more I read the more confused I'm getting and less I understand!

I have a distribution server deploying the Stream_TA_stream app to a universal forwarder on a Windows 10 PC (10.1.1.1) and this looks to be successful as I'm seeing the app along with my inputs.conf. Within my inputs.conf I have the splunk_stream_app_location set as http://10.1.1.11:8000/en-us/custom/splunk_app_stream/ 

10.1.1.11 is my Splunk Stream server with splunk_app_stream and splunk_TA_stream_wire_data installed. Under the Stream App config I have created a test stream looking for ICMP and under Distributed Forwarder Management a group with HEC off and an endpoint URL http://10.1.1.1.windows.uf:8088 

In Matched Forwarders should I be seeing my Win10 PC 10.1.1.1 in the Preview of matched Forwarders?

I have used Wireshark and can see comms on tcp port 8000 including the http 'ping' and an http 200 OK response but no other communications on any other port. Can anyone shed some light on what should happen next and how the Stream config is ‘shared’?

Any help/advise would be greatly appreciated.

Cheers.

Paul.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...