Splunk Stream on-premise deployment architecture (2024)

To deploy Splunk Stream you install three Stream components on your Splunk software.

Product nameInstallation package nameInstalled file name
Splunk App for Streamsplunk_app_streamsplunk_app_stream/
Splunk Add-on for Stream ForwardersSplunk_TA_streamSplunk_TA_stream/
Splunk Add-on for Stream Wire DataSplunk_TA_stream_wire_dataSplunk_TA_stream_wire_data/

Splunk Stream also provides Independent Stream Forwarders (ISF). ISF installation is packaged as a binary file <streamfwd> in the Splunk App for Stream package.

For more about Splunk Stream components, see Splunk Stream installation package overview in this manual.

Splunk Stream supports most deployment architectures:

  • Managed Splunk Cloud deployments
  • Distributed deployment configurations, including deployment servers and indexer clusters
  • Single instance deployments, where a single instance of Splunk Enterprise is both the indexer and the search head
  • Independent Stream Forwarders (ISF) on compatible Linux machines

Single instance deployment

When you install Splunk Stream on a single Splunk Enterprise instance, that instance serves as both search head and indexer and provides both search and storage capability. A single instance deployment can support one or two users running concurrent searches, which is ideal for a small test environment. For single instance installation instructions, see Install Splunk Stream on a single instance in this manual.

Distributed Splunk Stream deployment

A Splunk Stream distributed deployment can capture network event data from multiple network devices, including NICs, switches, and routers. A distributed deployment can be used in medium and large enterprise network infrastructures. For distributed installation instructions, see Install Splunk Stream in a distributed environment in this manual.

A distributed deployment for Splunk Stream includes the following deployment locations and Splunk Stream components:

Splunk deployment locationSplunk Stream component
search headsThe Splunk App for Stream (splunk_app_stream) and Splunk Add-on for Stream Wire data (Splunk_TA_stream_wire_data) must be installed on search heads.

You can optionally install Splunk Add-on for Stream Forwarders (splunk_TA_stream) if you want to collect data from the search head or want to use the PCAP upload.

indexersSplunk Add-on for Stream Wire Data (Splunk_TA_stream_wire_data) must be installed on all indexers for searching and parsing. Splunk Add-on for Stream Wire Data contains both search and index time knowledge objects.
universal forwardersThe Splunk Add-on for Stream Forwarders (Splunk_TA_stream) must be installed on universal forwarders where you want to capture network data. For dedicated wire capture in Linux environments without a universal forwarder, use the Independent Stream Forwarder (ISF). For more information, see Network collection architectures in this manual
heavy forwarderIf you use a heavy forwarder in your Splunk Stream configuration, the Splunk Add-on for Stream Forwarders (Splunk_TA_stream) must be installed on universal or heavy forwarders where you want to capture network data. You must also install the Add-on for Stream Wire Data (Splunk_TA_stream_wire_data) on your heavy forwarder wherever that index performs pipeline processing.
deployment serverUse the Splunk deployment server to distribute The Splunk Add-on for Stream Forwarders package (Splunk_TA_stream) to universal forwarders across a distributed deployment. When you upgrade to a new version of Splunk Stream, the deployment server detects whether a new version of The Splunk Add-on for Stream Forwarders exists. If a new version is found, all universal forwarders subscribed as deployment clients pull and install the new version of the add-on. For more information, see
  • Deployment server provisioning in Upgrading Splunk Enterprise Instances.
  • Components of a Splunk Enterprise deployment in the Splunk Enterprise Capacity Planning Manual.
Independent Stream Forwarder (ISF)The ISF is a standalone Stream forwarder. The ISF sends captured network data to Splunk using the HTTP event collector, and does not require a Splunk universal forwarder to collect wire data. It is helpful in networks and deployments where a universal forwarder cannot be installed. See Install an Independent Stream Forwarder

How a distributed Splunk Stream deployment works

In a typical distributed deployment, the Splunk Add-on for Stream Forwarders is installed on universal forwarders as Splunk_TA_Stream. Once installed, the forwarder captures network event data on local NICs, such as each node of a subnet environment, or from a network SPAN or TAP. For more information about data collection, see Network collection architectures in this manual.

The network data that a Stream forwarder captures depends on the specific protocols and fields that you select when you configure a stream using the Configure Streams UI that the Splunk App for Stream provides when you install it. The Stream forwarder sends that captured event data to indexers using the Splunk Add-on for Stream Wire Data (Splunk_TA_stream_wire_data).

Splunk_TA_stream/local/inputs.conf stores the location of the Splunk App for Stream (splunk_app_stream) installation, . The Stream forwarder uses this location to ping the Splunk App For Stream over HTTP port 8000. If the Stream forwarder detects a change in the Splunk Stream configuration, the Stream forwarder sends an API request to the endpoint to get the latest configuration data.

For more information about configuring the Splunk Add-on for Stream Forwarders, see Configure Stream Forwarders in this manual.

Splunk Stream on-premise deployment architecture (2024)

References

Top Articles
Kunitsu-Gami: Path Of The Goddess - Achievement/Trophy Guide
Steam Deck Acting Up? Here’s How to Reinstall Steam OS and Get Back to Gaming - UNIQUE NEWS
Fort Morgan Hometown Takeover Map
Truist Bank Near Here
Uca Cheerleading Nationals 2023
Inducement Small Bribe
Craigslist Cars Augusta Ga
Plaza Nails Clifton
Health Benefits of Guava
La connexion à Mon Compte
Bucks County Job Requisitions
Horoscopes and Astrology by Yasmin Boland - Yahoo Lifestyle
Holly Ranch Aussie Farm
27 Places With The Absolute Best Pizza In NYC
Flat Twist Near Me
Buckaroo Blog
Power Outage Map Albany Ny
Premier Reward Token Rs3
2015 Honda Fit EX-L for sale - Seattle, WA - craigslist
U Break It Near Me
Race Karts For Sale Near Me
Mikayla Campinos Laek: The Rising Star Of Social Media
Mccain Agportal
Dwc Qme Database
Dcf Training Number
Wkow Weather Radar
Relaxed Sneak Animations
Riverstock Apartments Photos
Reserve A Room Ucla
Askhistorians Book List
Gncc Live Timing And Scoring
Vlacs Maestro Login
1475 Akron Way Forney Tx 75126
Publix Daily Soup Menu
Chicago Pd Rotten Tomatoes
Flixtor Nu Not Working
Chattanooga Booking Report
Seymour Johnson AFB | MilitaryINSTALLATIONS
Bbc Gahuzamiryango Live
How To Paint Dinos In Ark
2008 DODGE RAM diesel for sale - Gladstone, OR - craigslist
Zasilacz Dell G3 15 3579
NHL training camps open with Swayman's status with the Bruins among the many questions
888-333-4026
Legit Ticket Sites - Seatgeek vs Stubhub [Fees, Customer Service, Security]
Hk Jockey Club Result
Hanco*ck County Ms Busted Newspaper
Sky Dental Cartersville
Meet Robert Oppenheimer, the destroyer of worlds
Leland Westerlund
Dlnet Deltanet
Southern Blotting: Principle, Steps, Applications | Microbe Online
Latest Posts
Article information

Author: Rev. Porsche Oberbrunner

Last Updated:

Views: 6647

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Rev. Porsche Oberbrunner

Birthday: 1994-06-25

Address: Suite 153 582 Lubowitz Walks, Port Alfredoborough, IN 72879-2838

Phone: +128413562823324

Job: IT Strategist

Hobby: Video gaming, Basketball, Web surfing, Book restoration, Jogging, Shooting, Fishing

Introduction: My name is Rev. Porsche Oberbrunner, I am a zany, graceful, talented, witty, determined, shiny, enchanting person who loves writing and wants to share my knowledge and understanding with you.