Splunk Stream

Installation and Configuration Manual

This documentation does not apply to the most recent version of Splunk Stream. For documentation on the most recent version, go to the latest release.

Source and sourcetype syntax

This table summarizes Splunk App for Stream source and sourcetype search syntax:

Stream 6.1.0 or later Example
Syntax source=stream:<stream-id> sourcetype=stream:<protocol>
Search for a specific <stream-id> source=stream:<stream-id> source=stream:http, source=stream:tcp
Search for all <protocol> streams sourcetype=stream:<protocol> sourcetype=stream:http, sourcetype=stream:tcp

Note: The name that Splunk App for Stream assigns to an individual <stream-id> is the same as the underlying protocol.

Last modified on 06 July, 2015
Stream capture configuration basics   Supported protocols

This documentation applies to the following versions of Splunk Stream: 6.3.0, 6.3.1, 6.3.2, 6.4.0, 6.4.1, 6.4.2, 6.5.0, 6.5.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters