Getting Data In

Splunk Stream TA stops streamfwd

skywalker
Observer

Hi Splunkers,

Is there any way to get rid of this knonw issue on Stream app ? 

Currently, I'm collecting DNS logs via Stream App on windows servers and streamfw.exe stopping without any reason somehow but UF is still running. This is a known issue written in the Stream docs.

When I dig into the internal logs and server logs, I couldn't find any related logs. 

now, I wrote a py to add a new txt file on Deployment server and reload the class then erase it for every 12 hours.

this is my little workaround but Its not efficient, I can't know when  they stops streaming and it means losing data till UFs restart time. 

Do you guys any other workaround for that ? 

 

the known issue is;

Windows: Capture stops with "pcap_loop returned error code -1 read error: PacketReceivePacket failed; network capture stopped" and isn't restarted

Workaround:
Manually re-configure streams for the forwarder to resume or restart Splunk Forwarder service in Windows

 

 

 

Labels (3)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...