<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to ingest PCAP files into Splunk? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457294#M56334</link>
    <description>&lt;P&gt;I'd also suggest to use the PCAP analyzer app linked above. Works well for analyzing traces.&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2019 10:01:13 GMT</pubDate>
    <dc:creator>skalliger</dc:creator>
    <dc:date>2019-08-16T10:01:13Z</dc:date>
    <item>
      <title>How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457285#M56325</link>
      <description>&lt;P&gt;I tried to ingest the captured pcap files manually using the following documentation and I don't see that file being indexed.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/UseStreamtoparsePCAPfiles"&gt;https://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/UseStreamtoparsePCAPfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;When I try the first option mentioned in the above documentation, all I see is my inputs.conf growing in size with my pcap file data, but it is not indexed into Splunk.&lt;/P&gt;

&lt;P&gt;When I try the second option, I don't see anything working.&lt;/P&gt;

&lt;P&gt;Can you please give me some leads on how to index the Pcap files.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 11:58:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457285#M56325</guid>
      <dc:creator>manikanta461</dc:creator>
      <dc:date>2018-07-25T11:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457286#M56326</link>
      <description>&lt;P&gt;It's not possible for your PCAP data to be saved in your inputs.conf file.  Are you sure of what you're seeing?&lt;/P&gt;

&lt;P&gt;How are you trying to find the data?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 13:33:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457286#M56326</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-07-25T13:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457287#M56327</link>
      <description>&lt;P&gt;Yeah,  this is the file "bfd-raw-auth-simple.pcap" which I tried to index into Splunk using the first method mentioned here, &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/UseStreamtoparsePCAPfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/UseStreamtoparsePCAPfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This is my inputs.conf file present in the location: "#SPLUNK_HOME/etc/apps/splunk_app_stream/local"&lt;BR /&gt;
[upload_pcap://PCAP]&lt;BR /&gt;
index = 1_mani_test&lt;BR /&gt;
pcap_file = FieldStorage('pcap_file', 'bfd-raw-auth-simple.pcap', '\xd4\xc3\xb2\xa1\x02\x00\x04\x00\x00\x00\x00\x00\x00\x00\x00\x00\xff\xff\x00\x00\x01\x00\x00\x00/w\x07\x00^@\x05\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x00\x00\x00\n\x11/X\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secretN\n\x90@/w\x07\x00\x9eM\x08\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x01\x00\x00\n\x11/W\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\xc2\x82\xde\x8d/w\x07\x00\xdeZ\x0b\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x02\x00\x00\n\x11/V\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secretJ\xafP//w\x07\x00\x1eh\x0e\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x03\x00\x00\n\x11/U\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\xcf\x90\xe7e0w\x07\x00\x1e3\x02\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x04\x00\x00\n\x11/T\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\x1b\xf2=\xb10w\x07\x00^@\x05\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x05\x00\x00\n\x11/S\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\x99\xa0\xdd\x860w\x07\x00\x9eM\x08\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x06\x00\x00\n\x11/R\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\x11\x8dS$0w\x07\x00\xdeZ\x0b\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x07\x00\x00\n\x11/Q\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\x94\xb2\xe4n0w\x07\x00\x1eh\x0e\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x08\x00\x00\n\x11/P\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\xf8N\x96V1w\x07\x00\x1e3\x02\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\t\x00\x00\n\x11/O\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret)t\xf4\xb51w\x07\x00^@\x05\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\n\x00\x00\n\x11/N\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\xa1Yz\x171w\x07\x00\x9eM\x08\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x0b\x00\x00\n\x11/M\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret$f\xcd]1w\x07\x00\xdeZ\x0b\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x0c\x00\x00\n\x11/L\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\xf0\x04\x17\x891w\x07\x00\x1eh\x0e\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\r\x00\x00\n\x11/K\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secretrV\xf7\xbe2w\x07\x00\x1e3\x02\x00O\x00\x00\x00O\x00\x00\x00\x00\x00\x01\x00\x00\x01\x00\x10\x94\x00\x00\x02\x08\x00E\x00\x00=\x00\x0e\x00\x00\n\x11/J\xc0U\x01\x02\xc0\x00\x00\x01\x04\x00\x0e\xc8\x00)r1 D\x05!\x00\x00\x00\x01\x00\x00\x00\x00\x00\x0fB@\x00\x0fB@\x00\x00\x00\x00\x01\t\x02secret\xfa{y\x1c')&lt;BR /&gt;
repeat = 0&lt;BR /&gt;
systemTime = 1&lt;/P&gt;

&lt;P&gt;I tried to find the data by searching in the index I mentioned above, which is "1_mani_test"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457287#M56327</guid>
      <dc:creator>manikanta461</dc:creator>
      <dc:date>2020-09-29T20:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457288#M56328</link>
      <description>&lt;P&gt;I suggest you try one of the other methods for setting up PCAP ingestion.  From my reading of the doc, configurations should be in streamfwd.conf, not inputs.conf.  See the Examples section at &lt;A href="http://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/UseStreamtoparsePCAPfiles#Examples"&gt;http://docs.splunk.com/Documentation/StreamApp/7.1.2/DeployStreamApp/UseStreamtoparsePCAPfiles#Examples&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 13:07:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457288#M56328</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-07-26T13:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457289#M56329</link>
      <description>&lt;P&gt;Yeah, I tried the other two methods as well. But I'm not able to get my files to Splunk.&lt;BR /&gt;
when I try the second method, this is the error which I get.&lt;/P&gt;

&lt;P&gt;[root@fr0-1z00-10 bin]# ./streamfwd -r /mnt/Data/Pcapfiles/bfd-raw-auth-simple.pcap&lt;BR /&gt;
08:01:15.421 INFO  stream.CaptureServer - Found DataDirectory: /opt/splunk/etc/apps/Splunk_TA_stream/data&lt;BR /&gt;
08:01:15.421 INFO  stream.CaptureServer - Found UIDirectory: /opt/splunk/etc/apps/Splunk_TA_stream/ui&lt;BR /&gt;
08:01:16.319 FATAL stream.main - Failed to start streamfwd, the process will be terminated: Unable to ping server (c060ec11-3abe-4858-bd1b-25edb89f02f5): U                            nable to establish connection to localhost: Connection refused&lt;/P&gt;

&lt;P&gt;Regarding the third method, I've appended my streamfwd.conf with the following contents, and I've performed a restart, but there was no success&lt;/P&gt;

&lt;P&gt;[streamfwd]&lt;BR /&gt;
streamfwdcapture.0.offline = true&lt;BR /&gt;
streamfwdcapture.0.interface = /mnt/Data/Pcapfiles&lt;/P&gt;

&lt;P&gt;However, I suspect the issue might be in how I have installed my Stream App.&lt;BR /&gt;
I haven't performed an SSL certification. Is it because of that? and moreover I have installed the app from my Splunk UI, which I run on my windows PC, but I have actually installed Splunk on my Linux machine.&lt;BR /&gt;
I login to the Linux machine using ssh&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:37:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457289#M56329</guid>
      <dc:creator>manikanta461</dc:creator>
      <dc:date>2020-09-29T20:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457290#M56330</link>
      <description>&lt;P&gt;You're exceeding my experience with Stream, but I believe you've installed it correctly.  You may want to try installing it directly on the Linux box if you can.&lt;/P&gt;

&lt;P&gt;Check your firewalls to make sure they're not blocking Stream traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 12:54:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457290#M56330</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-07-27T12:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457291#M56331</link>
      <description>&lt;P&gt;try &lt;A href="https://splunkbase.splunk.com/app/2748/"&gt;https://splunkbase.splunk.com/app/2748/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 13:02:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457291#M56331</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2018-07-27T13:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457292#M56332</link>
      <description>&lt;P&gt;Thanks for your comment, but that app needs Wireshark running on our server in order to index the Pcap files&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 13:11:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457292#M56332</guid>
      <dc:creator>manikanta461</dc:creator>
      <dc:date>2018-07-27T13:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457293#M56333</link>
      <description>&lt;P&gt;Were you able to figure this out? I am seeing the same issue.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 19:04:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457293#M56333</guid>
      <dc:creator>runnikrishnan_s</dc:creator>
      <dc:date>2019-08-15T19:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457294#M56334</link>
      <description>&lt;P&gt;I'd also suggest to use the PCAP analyzer app linked above. Works well for analyzing traces.&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 10:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457294#M56334</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2019-08-16T10:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457295#M56335</link>
      <description>&lt;P&gt;My understanding is that the pcap file upload via the Splunk Stream Web UI might have caused some kind of corruption. This may not be the right solution. However, this is a workaround that worked for me.&lt;BR /&gt;
1. delete the (growing) inputs.conf file (which apparently contains some binary data)&lt;BR /&gt;
2. delete the corresponding "data input" created via Splunk Web UI&lt;/P&gt;

&lt;P&gt;Now, as per option 2 in manual, run the command via CLI which should be something like this:&lt;BR /&gt;
./streamfwd -r &lt;/P&gt;

&lt;P&gt;This should successfully cause the pcap file to be ingested by Splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2019 19:10:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/457295#M56335</guid>
      <dc:creator>runnikrishnan_s</dc:creator>
      <dc:date>2019-08-16T19:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest PCAP files into Splunk?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/699743#M81098</link>
      <description>&lt;P&gt;Convert the pcap file to a text file before ingesting into splunk&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2024 17:30:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-to-ingest-PCAP-files-into-Splunk/m-p/699743#M81098</guid>
      <dc:creator>Abu-Zaynab</dc:creator>
      <dc:date>2024-09-21T17:30:32Z</dc:date>
    </item>
  </channel>
</rss>

