<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to make a script. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-make-a-script/m-p/171643#M34636</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;

&lt;P&gt;I hope you can help me with the next problem:&lt;/P&gt;

&lt;P&gt;I cant virtualize a tcpdump on my mac.&lt;BR /&gt;
I wish to get some information on en0, this means i need to change eth0 to en0.&lt;BR /&gt;
At this moment i have 0 events, and when i clone this script its not placed for SplunkViz but launcer.&lt;/P&gt;

&lt;P&gt;/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh eth1 should be :&lt;/P&gt;

&lt;P&gt;/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh en0 &lt;/P&gt;

&lt;P&gt;For some clearence:&lt;BR /&gt;
Everything that will be going trough my ethernet port ( en0) i would like to see in my SplunkViz.&lt;/P&gt;

&lt;P&gt;Any idea what i do wrong ?&lt;/P&gt;</description>
    <pubDate>Mon, 03 Mar 2014 15:50:45 GMT</pubDate>
    <dc:creator>sincerus</dc:creator>
    <dc:date>2014-03-03T15:50:45Z</dc:date>
    <item>
      <title>How to make a script.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-make-a-script/m-p/171643#M34636</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;

&lt;P&gt;I hope you can help me with the next problem:&lt;/P&gt;

&lt;P&gt;I cant virtualize a tcpdump on my mac.&lt;BR /&gt;
I wish to get some information on en0, this means i need to change eth0 to en0.&lt;BR /&gt;
At this moment i have 0 events, and when i clone this script its not placed for SplunkViz but launcer.&lt;/P&gt;

&lt;P&gt;/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh eth1 should be :&lt;/P&gt;

&lt;P&gt;/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh en0 &lt;/P&gt;

&lt;P&gt;For some clearence:&lt;BR /&gt;
Everything that will be going trough my ethernet port ( en0) i would like to see in my SplunkViz.&lt;/P&gt;

&lt;P&gt;Any idea what i do wrong ?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2014 15:50:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-make-a-script/m-p/171643#M34636</guid>
      <dc:creator>sincerus</dc:creator>
      <dc:date>2014-03-03T15:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to make a script.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-make-a-script/m-p/171644#M34637</link>
      <description>&lt;P&gt;I am using this tool by the way :&lt;/P&gt;

&lt;P&gt;&lt;A href="http://metasplunk.com/projects/particle" target="test_blank"&gt;http://metasplunk.com/projects/particle&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2014 15:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-make-a-script/m-p/171644#M34637</guid>
      <dc:creator>sincerus</dc:creator>
      <dc:date>2014-03-03T15:54:05Z</dc:date>
    </item>
  </channel>
</rss>

