All Apps and Add-ons

Splunk Stream change of heavy forwarder

_daver
Engager

Hi

I am running Splunk Stream in a SplunkCloud environment. I have a heavy fowarder (say hf01) that has stream app installed and it communicates with the splunk fowardwarders where Stream TA is running and pushes the latest config.

I have changed the heavy forwarder that has stream app installed from hf01 to hf03. How can I let my UF's know that now check hf03 instead of hf01 for configurations?

0 Karma
1 Solution

nabeel652
Builder

On all of your UF's (either manually or through config manager/deployment server) change the splunk_stream_app_location to new heavy forwarder. It should look like this:

[streamfwd://streamfwd]
splunk_stream_app_location = http://hf03:8000/en-US/custom/splunk_app_stream/
stream_forwarder_id = <Your fwdr id>
disabled = false

View solution in original post

nabeel652
Builder

On all of your UF's (either manually or through config manager/deployment server) change the splunk_stream_app_location to new heavy forwarder. It should look like this:

[streamfwd://streamfwd]
splunk_stream_app_location = http://hf03:8000/en-US/custom/splunk_app_stream/
stream_forwarder_id = <Your fwdr id>
disabled = false

nabeel652
Builder

BTW the location of the file would be:

[SPLUNK_HOME]/etc/apps/splunk_TA_stream/local/inputs.conf

_daver
Engager

Thanks @nabeel652
That worked!

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...