All Apps and Add-ons

Splunk Stream app does not send configuration to Stream Forwarders

b_chris21
Communicator

Hello,

I have Splunk Stream app installed on my Search Head (Deployment Server) which controls the Stream Forwarders deployed on my Indexers (Deployment Clients).

Even though app is deployed and I receive stream data, whenever I change the configuration of my streams (remove fields from protocols, add IP blacklist filters etc) the configuration does not get applied on Stream Forwarders even though I have tried to restart them. No IP filtering is applied nor protocol fields are removed.

Any way I can troubleshoot that?

Thanks

Chris

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...