Splunk Cloud Platform

splunk stream

iherb_0718
Path Finder

All,

I have a few questions related to splunk stream

1) If a windows computer has splunk stream app installed and it has a UF installed, what are some differences in logging activity will I get between the two?

2) Does the splunk stream app get deployed from the deployment server just as the UF does?

3) Does splunk stream log just web traffic?

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

@iherb_0718,

I assume you installed The Splunk App for Stream on Heavy Forwrder to manage Stream configuration on UFs.

You should install  "The Splunk Add-on for Stream Forwarders (Splunk_TA_stream)" on every client that you want to collect stream data.

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

0 Karma

iherb_0718
Path Finder

Scelikok, assume I have all the work for splunk stream done on the splunk side.  That is I got the splunk stream app deployed to the heavy forwarder.  This would still require an app on the client side?  The client already has a UF.  It wouldn't be just tweaking the UF conf files to get stream?

0 Karma

scelikok
SplunkTrust
SplunkTrust

@iherb_0718,

I assume you installed The Splunk App for Stream on Heavy Forwrder to manage Stream configuration on UFs.

You should install  "The Splunk Add-on for Stream Forwarders (Splunk_TA_stream)" on every client that you want to collect stream data.

 

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @iherb_0718,

You can find all information regarding Stream on Splunk docs below;

https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/AboutSplunkStream 

Answers to your questions;

1) Splunk Stream App cannot work standalone it should deployed to UF or Splunk Instance. It adds network traffic capture or PCAP ingestion capabilities to Splunk.

2) You can deploy from deployment server.

3) Supported protocols can be found in documentation. https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/ProtocolDetection  

If this reply helps you an upvote is appreciated.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...