New features
Splunk App for Stream version 6.4.0 adds these new features:
UI Enhancements:
- Configure Streams UI redesign, includes:
- Create New Stream wizard
- Simplified mode selection (Enabled/Estimate/Disabled).
- Improved bulk editing UI.
- "original/cloned" stream column.
- New Product Tour
- New pre-populated dashboards for HTTP, DNS, Database, and other protocols.
- New Stream Estimate dashboard lets you see data index volume stats without sending data to indexers.
- Improved app UI and navigation.
Default app configuration improvements:
- All streams in Estimate mode by default.
- Wire Data data source (Splunk_TA_Stream) enabled by default.
New streamfwd.xml
configuration parameter:
- <UsePacketMemoryPool>true|false</UsePacketMemoryPool>
New SSL fields:
- ssl_cipher_id
- ssl_cipher_name
- ssl_public_key_length
- certificate SHA1 and SHA256 hashes
New Top "N" Fields filter based on event count or aggregated fields.
Accelerated queueing and other Performance improvements.
Fixed Issues | Credits |
This documentation applies to the following versions of Splunk Stream™: 6.4.0
Feedback submitted, thanks!