Stream capture configuration basics
Use the Configure Streams UI inside Splunk App for Stream (splunk_app_stream
) to configure the specific network data protocols (such as http, tcp, dns, pop3, smtp and so on) that you want the streamfwd
binary to capture.
Use the streamfwd.conf
file in Splunk_TA_stream/local
to configure system-level parameters (specify IP address/ports, add network interfaces, enable SSL, and so on) for the streamfwd
binary. See Configure Stream forwarder in this manual.
Note: streamfwd
pings splunk_app_stream
at default intervals of 5 seconds. To change the ping interval, modify the PingInterval parameter value in streamfwd.conf
. For more information, see Stream Frowarder sizing guide in this manual.
Stream forwarder sizing guide | Source and sourcetype syntax |
This documentation applies to the following versions of Splunk Stream™: 6.5.0, 6.5.1, 6.6.0, 6.6.1, 6.6.2
Feedback submitted, thanks!