Splunk Enterprise

Stream Forwarder never come online

Footoasis0868
Explorer

Hi All,

Deployment: Single Instance Splunk Enterprise

What I want: install the Splunk_TA_stream on my universal forwarder to capture DNS traffic as stream

The doc I followed

The App and add-on are already installed

apps.jpg

The Splunk_TA_stream has been deployed to the UF:

forwarder.png

But I found that the streamfwd.exe is not running. Also I don't see the UF in the dashboard:

splunkapp.jpg

(only the splunk single instance itself is present, and it is even in Error Status)

 

Any insights for me to discover what went wrong?

 

Thank you in advance.

 

Labels (1)
Tags (1)
0 Karma

Footoasis0868
Explorer

Anyone who have idea on this??

 

Thanks in advance.

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @Footoasis0868,

Can you confirm if your Splunk instance GUI access is HTTPS enabled? If not your splunk_stream_app_location setting on UF must be http://xxxxx:8000/en-us/custom/splunk_app_stream/

Regarding your Splunk instance itself error state,  please confirm you run set_permissions.sh to be able to start streamfwd.exe

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

Footoasis0868
Explorer

Hi @scelikok ,

Thanks. I checked the URL, and it is an error page and I can't locate the requestid from the splunk internal logs.

error.png

Regarding the set_permissions.sh, yes, I have run it using root in my Splunk instance. Just make it clear, I don't need to run similar script on the Windows server where I deployed the Splunk_TA_Stream app, correct?

 

Thanks again.

 

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...