Getting Data In

Splunk Stream TA stops streamfwd

skywalker
Observer

Hi Splunkers,

Is there any way to get rid of this knonw issue on Stream app ? 

Currently, I'm collecting DNS logs via Stream App on windows servers and streamfw.exe stopping without any reason somehow but UF is still running. This is a known issue written in the Stream docs.

When I dig into the internal logs and server logs, I couldn't find any related logs. 

now, I wrote a py to add a new txt file on Deployment server and reload the class then erase it for every 12 hours.

this is my little workaround but Its not efficient, I can't know when  they stops streaming and it means losing data till UFs restart time. 

Do you guys any other workaround for that ? 

 

the known issue is;

Windows: Capture stops with "pcap_loop returned error code -1 read error: PacketReceivePacket failed; network capture stopped" and isn't restarted

Workaround:
Manually re-configure streams for the forwarder to resume or restart Splunk Forwarder service in Windows

 

 

 

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...