All Apps and Add-ons

Splunk Stream: Forwarder management group has no effect on clients

gustavomichels
Path Finder

Hello,

Trying to create a specific forwarder group in the Stream app. Using Stream 7.1.1 on a 6.6.1 Search Head Cluster.

In Distributed Forwarder Management, the group is created and the preview matches the nodes:

alt text

However, the change never takes effect and the hosts remain in the defaultgroup.

alt text

Any clues what is going on?

nathanluke86
Communicator

I have this issue also and believe the issue is caused by the Stream app on Splunk Cloud.

If I create a group within the app on my hybrid Search Head which I am using to configure streams it won't match a forwarder even though it has been discovered.

On Splunk Cloud, If I duplicate the group created on the Hybrid SH it will then match the forwarder on the Hybrid Sh.

I have been informed that configuring streams on Cloud is not allowed but I am struggling to find an alternative solution.

On Splunk Cloud the Stream TA is needed for the indexing layer but I am wondering whether removing the app from Cloud will it fix this issue.

Has anyone had any progress with this issue

0 Karma

cesaccenturefed
Path Finder

I'm also having this issue too. I'm using a search head cluster, my stream app location defined on the forwarder is the VIP sitting in front of the cluster. The forwarder is actively calling in so I'm not sure why my forwarder is not populating to my new group.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...