Version 7.2.0 of Splunk Stream contains the following known issues.
If no issues appear below, no issues have yet been reported:
|Date filed||Issue number||Description|
|2020-12-08||STREAM-4641, STREAM-4635||Update the actual hostname if stream events host has value $decideOnStartup|
Create the etc/system/local/inputs.conf file with the actual hostname manually.
|2020-08-20||STREAM-4522||ES configuration template disables NetFlow|
Look to be ES_IP_RAW this is the problem
The problem is on line 157 there is two commas:
"aggType": "value", "desc": "VXLAN Network Identifier", "enabled": true, "name": "vxlan_id", "term": "flow.vxlan-id" } ],
Remove the extra comma to make it look like:
"desc": "VXLAN Network Identifier",
|2020-01-06||STREAM-4301, STREAM-4409||Windows: Capture stops with "pcap_loop returned error code -1 read error: PacketReceivePacket failed; network capture stopped" and isn't restarted|
Manually re-configure streams for the forwarder to resume or restart Splunk Forwarder service in Windows
|2019-10-31||STREAM-4235||PCAP files are not getting ingested from UI in 7.2|
The workaround is to load pcap file from a command line. This can be done from any machine that has Stream TA installed. Invoke the streamfwd binary directly with the '-r' option: streamfwd -r <pcap file>
This documentation applies to the following versions of Splunk Stream™: 7.2.0