User's Guide

Table Of Contents
Part 1 Making File Level Splunk Modifications
195 of 218
Part 1 Making File Level Splunk Modifications
1. Connect to the Splunk server via SSH.
2. Enter cd $SPLUNK_HOME/etc/apps/splunk_app_stream/local.
3. Copy the streamfwd.conf file. (If there is no streamfwd.conf file present,
skip this step.)
4. Copy Extreme's version of the streamfwd.conf file and paste it into
streamfwd.conf. Alternately, merge Extreme's version of streamfwd.conf
settings into the existing streamfwd.conf file.
5. Enter cd $SPLUNK_HOME/etc/apps/Splunk_TA_stream/local.
6. Copy the streamfwd.conf file. (If there is no streamfwd.conf file present,
skip this step.)
7. Copy the streamfwd.conf file from the splunk_app_stream/local
directory to this directory.
8. Enter cd $SPLUNK_HOME/etc/apps/splunk_app_
stream/default/vocabulary.
9. Copy the extr.xml file to this directory.
10. Enter cd $SPLUNK_HOME/etc/apps/splunk_app_
stream/default/vocabulary/streams.
11. Make a copy of the netflow file.
12. Merge the contents of our extr.netflow file to the netflow file.
Part 2 Creating a New Stream using the Splunk
web UI
1. Log in to Splunk (by default, the web server is on port 8000).
2. Navigate to the Splunk Stream App.
3. Select Configure Streams from the Configuration menu.
4. Optionally, disable all existing streams if you installed Splunk Stream solely to
integrate Analytics flow data.