All Apps and Add-ons

Splunk Stream is not listening for netflow data

rtiulmankov
Explorer

I've installed Splunk Stream v 7.1.1. And streamfwd proccess is running. I'm trying to make it listen for the netflow information from the router:

[streamfwd]
port = 8890
ipAddr = 127.0.0.1
netflowReceiver.0.ip = 127.0.0.1
netflowReceiver.0.port = 9998
netflowReceiver.0.decoder = netflow

But I don't see any process listening on UDP port 9998.

What can be the issue?

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

@rtiulmankov do you have a netflow stream enabled? Is there anything in streamfwd.log?

0 Karma

rtiulmankov
Explorer

@vshcherbakov_splunk there was nothing bad in streamfwd.log, just that the service started. I've reinstalled splunk stream using package and it's listening on the correct port now.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...