Stream data capture configuration basics
Use the Configure Streams UI inside Splunk App for Stream (splunk_app_stream
) to configure the specific network data protocols (such as http, tcp, dns, pop3, smtp and so on) that you want the streamfwd
binary to capture.
Use the streamfwd.conf
file in Splunk_TA_stream/local
to configure system-level parameters (specify IP address/ports, add network interfaces, configure pcap file ingestion, enable SSL, and so on) for the streamfwd
binary. See Configure Stream forwarder in this manual.
Note: streamfwd
pings splunk_app_stream
at default intervals of 5 seconds. To change the ping interval, modify the pingInterval
parameter value in streamfwd.conf
. For more information, see Stream Forwarder sizing guide in this manual.
Network collection architectures | Splunk Stream search syntax |
This documentation applies to the following versions of Splunk Stream™: 7.1.0, 7.1.1
Feedback submitted, thanks!