Stream data capture configuration basics
Use the Configure Streams UI in Splunk App for Stream (splunk_app_stream
) to configure the specific network data protocols (such as http, tcp, dns, pop3, smtp and so on) that you want the streamfwd
binary to capture.
Use the streamfwd.conf
file in Splunk_TA_stream/local
to configure system-level parameters for the streamfwd
binary. System-level parameters you can configure include specifying IP address/ports, adding network interfaces, configuring pcap file ingestion, or enabling SSL. See Configure Stream forwarder in this manual.
Note: streamfwd
pings splunk_app_stream
at default intervals of 5 seconds. To change the ping interval, modify the pingInterval
parameter value in streamfwd.conf
. For more information, see Stream Forwarder sizing guide in this manual.
Network collection architectures | Splunk Stream search syntax |
This documentation applies to the following versions of Splunk Stream™: 7.1.2, 7.1.3, 7.2.0
Feedback submitted, thanks!