Hi banaie, There is no template called Splunk. If you search on /opt/streamfwd/configs, you will only find two templates, one for ES, and another for ITSI. You have to create another directory under /optstreamfwd/configs (I called it Splunk) and select and modify for your needs the xml files you will find on these templates. I started modifying those xml under the Default directory of Stream App located at the indexer, wich seam to have the same format. If it doesn't work, check the log file located at /opt/streamfwd/var/log and post some errors here.
... View more