Knowledge Management

How to confirm if Netflow or other data is being collected under the app:"splunk_app_stream"

nathant089
New Member

On my Splunk Cloud instance, there is an app called: "splunk_app_stream" that is currently disabled under the 'App' settings.

Before I go uninstalling this app, I would like to know if there is a way to confirm if Splunk is ingesting data for that app before uninstalling it (even though it's disabled)?

0 Karma

uagrawal_splunk
Splunk Employee
Splunk Employee

1) Navigate to Stream App -> Admin Dashboards -> Stream Forwarder Status dashboard. Check the status of the Stream forwarder. Also, check the Total events dashboard. From there you can identify whether stream app is indexing data or not.
2) In the Search bar, run this query sourcetype= stream:*. If search query returns no result, then Stream App is not indexing any data into Splunk.

0 Karma
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...