Splunk App for Stream

Splunk App for Stream is a scalable and easy-to-configure software solution that captures real-time streaming wire data from anywhere in your datacenter or from any public Cloud infrastructure.

Benefit from this new class of data in Splunk and correlate it with logs, events and metrics to enhance Operational Intelligence across a variety of use cases.

Capture only the relevant wire data for analytics, through filters and aggregation rules. Manage wire data volumes with fine-grained precision by selecting or deselecting protocols and associated attributes within the App interface.

Rapidly deploy wire data collection, from the App interface, to gain real time network visibility that is otherwise unavailable from cloud implementations and hard to achieve with traditional datacenters. Respond quickly to any issue with a simple interface-driven installation, centralized deployment and configuration across IT environments of all sizes.

Release Notes

Splunk App for Stream lets you:

• Capture wire data across distributed infrastructures, from the network perimeter and endpoints in public, private or hybrid clouds using a single software solution.
• Control and manage wire data volumes with fine-grained precision by selecting or deselecting protocols and associated attributes within the app interface.
• Clone built-in streams, and define filters and aggregation rules to capture meaningful data for analyses.
• Create ephemeral streams to capture data over specific time intervals for pinpoint analysis(in conjunction with supported Splunk apps).
• Whitelist or blacklist data capture from specific IP addresses and subnets with the interface.
• Decrypt SSL-encrypted traffic with RSA keys for data completeness.
• Scale the installation and configuration with interface-driven installation and centralized management.
• Correlate application and infrastructure data such as logs, events and metrics with wire data to gain valuable insights and enhance operational intelligence.

Install Splunk App for Stream

  1. Click Download on this page. The splunk_app_stream tar.gz installer file downloads to your computer.
  2. Log into Splunk Web.
  3. Click Apps > Manage Apps.
  4. Click Install App from File.
  5. Upload the splunk_app_stream tar.gz installer file.
  6. Restart Splunk.

For detailed installation instructions, see Install Splunk App for Stream.

Splunk App for Stream components

Splunk App for Stream installs the following components:

  • Splunk_TA_stream: Splunk_TA_stream contains the streamfwd binary (stream forwarder), which passively captures event data from network devices, and sends that data to Splunk Enterprise indexers using a "Wire Data" modular input.

  • splunk_app_stream: splunk_app_stream provides configuration management for Splunk_TA_stream. You can use splunk_app_stream to configure event capture for multiple network protocols. See Supported Protocols.

Important: You must be running splunkd with "root" privileges for the streamfwd binary to capture data. To set privileges on *nix:

  1. Go to $SPLUNK_HOME/etc/apps/Splunk_TA_stream.
  2. Issue the command sudo ./setuid.sh

On Windows, you must be running as administrator or install winpcap separately.

Source and sourcetype syntax

All captured events have "source=stream:stream-id" and "sourcetype=stream:protocol", where ID is typically the name of a protocol. For example, "sourcetype=stream:http."

Splunk Enterprise version requirements

Splunk App for Stream version 6.4.1 requires Splunk Enterprise version 6.1.x or later. Splunk Enterprise version 6.3.x is recommended.

For complete Splunk App for Stream documentation, see Splunk App for Stream documentation.

23 ratings

Version 6.4.1

Splunk Supported

Built by Splunk Inc