I am having trouble getting stream working in a distributed deployment with heavy forwarders.
A few points:
If Stream is pushed to universal forwarders (UFs) from a deployment server (DS), when the stream forwarders sends configuration changes to the UF, wouldn't the app with the configurations on the UF be over-written after the UF checks in to the DS?
We have a DMZ, with a heavy forwarder (HF) that also servers as a DS. This system also has stream, because the systems in the DMZ cannot talk to the stream server located on the internal network. I had to also turn the DS/HF into a search head and tell it how to reach the indexers for the stream app to work.
I see where stream thinks it is collecting events from a few of the systems, but I am not seeing events???