All Apps and Add-ons

Splunk Stream TA with capturing capability turned off

support0
Path Finder

Hi there,

I have deployed Splunk Stream on a distributed environment to ingest DNS first.

I have followed howtos here and there and everything is fine with collected data.

One thing remains unclear.

I have Splunk Stream + Stream TA on my ES Search Head
Stream TA on another Search Head > just for parsing
Stream TA on Deployement Server > just for parsing
Stream TA on Indexer > for indexing, timestamp etc.
Stream TA + inputs on DNS servers

However I do receive error messages from SH, DS & IDX mentioning permission issues :

Unable to initialize modular input "streamfwd" defined inside the app "Splunk_TA_stream": Introspecting scheme=streamfwd: Unable to run "/opt/splunk/etc/apps/Splunk_TA_stream/linux_x86_64/bin/streamfwd --scheme": child failed to start: Permission denied

I have already used set_permissions.sh so that might be due to the the fact that Splunk is running as non-root.

However, on these instance, the TA is not there for capturing any stream, so isn't better to just turn off TA's network capturing capability ?

I am wondering what files should I removed from the TA to do this and if this is is a good idea to do so.

Thanks in advance,

Tags (1)
0 Karma

support0
Path Finder

Hi,

Thanks for the help,

Actually I had the same issue than the one described there :

https://answers.splunk.com/answers/475630/splunk-app-for-stream-why-does-set-permissionssh-s.html

So I resolved it the same way.

Thanks

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Have you checked whether streamfwd modular input is disabled on IDX/SH/DS instances?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...