Skip to main content
Solved

SplunkTCP Source with UF using compress=true

  • March 11, 2025
  • 0 replies
  • 8 views

If Splunk Universal Forwarders are configured with compressed = true in the outputs.conf, can the Cribl Stream SplunkTCP source receive from them properly?

Best answer by Clint Sharp

Compression is not supported. See How to Architect Your LogStream to LogStream Data Flows for a good overview of features support.

Also, this was discussed in this thread in the Slack community: Slack.

  • Cribl Founder
  • Answer
  • March 11, 2025

Compression is not supported. See How to Architect Your LogStream to LogStream Data Flows for a good overview of features support.

Also, this was discussed in this thread in the Slack community: Slack.