Getting Data In

How to forward Netflow data using Stream addon on UF to Indexers on port 9997 ?

dm1
Contributor

I am looking to collect Netflow data on a host, where I have installed Splunk UF along with Stream addon.

I want to send this data to a client's Splunk Indexer,  on port 9997.

While the doc states, configure indexer to receive Stream data on port 9997, however, in the "Set up data collection on remote machines" section, it requires HEC tokens for the indexer.

Is there a way to configure the addon to to Netflow data to Indexers on port 9997 instead of on the HEC token ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...