<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: View Packet Payload in Stream in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179175#M17537</link>
    <description>&lt;P&gt;Correct, the src_content and dest_content fields are only populated in just under 5% of our events (this is combined after enabling src_content &amp;amp; dest_content for both TCP &amp;amp; UDP).&lt;/P&gt;

&lt;P&gt;What are the packet count fields, packets_in &amp;amp; packets_out?&lt;/P&gt;

&lt;P&gt;Is there something else I need to do to view the packet payload within Splunk or will I need to generate some pcaps to start creating parsers for our custom apps?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 20:24:03 GMT</pubDate>
    <dc:creator>kbecker</dc:creator>
    <dc:date>2020-09-28T20:24:03Z</dc:date>
    <item>
      <title>View Packet Payload in Stream</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179173#M17535</link>
      <description>&lt;P&gt;Starting looking at Stream and have a good amount of tcp/udp flow events in which app is "unknown". How can I view the packets payload in Splunk in order to parse out data/create custom streams?  I have enabled src_content but this doesn't show the payload for "unknown" events.&lt;/P&gt;

&lt;P&gt;Thanks in advance.  &lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 13:54:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179173#M17535</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2015-06-26T13:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: View Packet Payload in Stream</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179174#M17536</link>
      <description>&lt;P&gt;Do you mean the src_content field is not present for flows that could not be classified (app is "unknown")? If so, it's probably because Stream didn't capture any payload packets since the src_content data is captured independently from flow classification. I'd suggest checking the packet count fields to see if these flows have anything substantial. Enabling the dest_content field may also be of value.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:23:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179174#M17536</guid>
      <dc:creator>vshcherbakov_sp</dc:creator>
      <dc:date>2020-09-28T20:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: View Packet Payload in Stream</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179175#M17537</link>
      <description>&lt;P&gt;Correct, the src_content and dest_content fields are only populated in just under 5% of our events (this is combined after enabling src_content &amp;amp; dest_content for both TCP &amp;amp; UDP).&lt;/P&gt;

&lt;P&gt;What are the packet count fields, packets_in &amp;amp; packets_out?&lt;/P&gt;

&lt;P&gt;Is there something else I need to do to view the packet payload within Splunk or will I need to generate some pcaps to start creating parsers for our custom apps?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 20:24:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179175#M17537</guid>
      <dc:creator>kbecker</dc:creator>
      <dc:date>2020-09-28T20:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: View Packet Payload in Stream</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179176#M17538</link>
      <description>&lt;P&gt;Yes, I'd start with checking packets_in and packets_out fields. There are also data_packets_in and data_packets_out fields indicating the number of TCP payload packets. I'd also suggest upgrading App for Stream to v 6.3 as it contains improvements in the flow classification logic.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:36:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/View-Packet-Payload-in-Stream/m-p/179176#M17538</guid>
      <dc:creator>vshcherbakov_sp</dc:creator>
      <dc:date>2020-09-29T06:36:35Z</dc:date>
    </item>
  </channel>
</rss>

