Stream data capture configuration basics
Writer notes: This topic is not really helpful. Should be made a complete topic or deleted.
Use the Configure Streams Stream Configuration user interface in Splunk Web to set up your configuration:
- Configuing the specific network data protocols (such as http, tcp, dns, pop3, smtp and so on) that you want the
streamfwd
binary to capture. - TBD
You must have Splunk_TA_Stream
installed to configure these parameters. System-level parameters you can configure include:
- Specifying IP address and ports
- Adding network interfaces
- Configuring PCAP file ingestion
- Configuring and enabling SSL
See Configure Stream forwarder in this manual.
The Splunk TA Stream Forwarder Splunk_App_Stream
pings the Splunk App for Stream splunk_app_stream
at default intervals of 5 seconds. To change the ping interval, modify the pingInterval
parameter in streamfwd.conf
.
For more information, see Stream Forwarder sizing guide in this manual.
This documentation applies to the following versions of Splunk Stream™: 7.3.0
Feedback submitted, thanks!