<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring a wireshark file using Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28663#M4901</link>
    <description>&lt;P&gt;i.e. the correct timestamp recognition is in place, and line breaking is taking place correctly. It is easier to make changes to timestamp recognition/line breaking here, as Splunk will assist in the setup (and even show you what changes are being made to the props.conf file).&lt;/P&gt;

&lt;P&gt;If this answers your question, can you mark the answer as accpeted (the tick next to my answer), as this will show others the question does not require more attention, and helps those looking for answers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Apr 2012 08:02:54 GMT</pubDate>
    <dc:creator>MHibbin</dc:creator>
    <dc:date>2012-04-17T08:02:54Z</dc:date>
    <item>
      <title>Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28649#M4887</link>
      <description>&lt;P&gt;How does the Splunk monitor a Wireshark capture file in its textual form in windows 7? I converted the wireshark pcap file to the txt file. Based on what i read from the Splunk answers forum : &lt;A href="http://splunk-base.splunk.com/answers/2922/splunk-monitoring-a-wireshark-file"&gt;http://splunk-base.splunk.com/answers/2922/splunk-monitoring-a-wireshark-file&lt;/A&gt; , jerrad installed the Splunk Light Forwarder and have it monitor the textual file from the  /tshark/splunk/gtp/ directory. &lt;/P&gt;

&lt;P&gt;So that means i can set up a Splunk light forwarder using Splunk web right? I followed the instructions from the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Deployaforwarder"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Deployaforwarder&lt;/A&gt; which teaches how to set up the light heavy forwarders. The instruction states a heavy forwarder has to be set up before setting up a light forwarder, which im not sure of cos i clicked add new  against the configure forwarding section,  which i have entered the host and port no and saved the settings. &lt;/P&gt;

&lt;P&gt;However, i'm quite new to Splunk and now im using Splunk 4.3. When i was about to go to the manager in the Splunk Web to set up the forwarder, the instruction in the forwarding and recieving section in manager states that CAUTION: This will immediately turn off Splunk Web if the light forwarder in the Splunk web. So i would like to know if the light forwarder is the one that monitors the converted wireshark captured file as txt file since Splunk 4.3 ? &lt;/P&gt;

&lt;P&gt;I hope this would not be treated as a duplicate question. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28649#M4887</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T06:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28650#M4888</link>
      <description>&lt;P&gt;Hi misteryuku&lt;/P&gt;

&lt;P&gt;just setup everything as you want it on the heavy forwarder and if you get the data the way you want it, go into UI - Manager - Apps and enable the light forwarder. This will disable the web UI and some other features of splunk.&lt;/P&gt;

&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28650#M4888</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-04-17T06:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28651#M4889</link>
      <description>&lt;P&gt;Disabling the web UI and some other features of Splunk sounds like there would be disadvantages. I m quite skeptical. Cos my goal is to monitor the converted wireshark capture file in windows 7 txt file using Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:16:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28651#M4889</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T06:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28652#M4890</link>
      <description>&lt;P&gt;enabling the light forwarder will only disable the web UI which is only used for config changes for example and data inputs to the light forwarder will not be parsed (probs.conf and transform.conf will not be processed on the light forwarder). you still will be able to monitor the directory &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; but you reduce the system load and the footprints in the data caused by splunk&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:20:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28652#M4890</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-04-17T06:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28653#M4891</link>
      <description>&lt;P&gt;When i clicked enable light forwarder, the splunk web prompted me to restart Splunk. and there was no restart splunk button and i have to go to the Splunk's CLI. So how do i restart splunk using the CLI?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28653#M4891</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T06:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28654#M4892</link>
      <description>&lt;P&gt;change to SPLUNK_HOME (which is the directory where Splunk is installed) and execute as splunk user:&lt;BR /&gt;
./bin/splunk restart (on *inx)&lt;BR /&gt;
\bin\splunk.exe restart (on Windows)&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:29:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28654#M4892</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-04-17T06:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28655#M4893</link>
      <description>&lt;P&gt;My PC is running the Windows 7 Platform. Is it done in the Windows 7 cmd line interface? calling cd?? I'm quite lost .....&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:38:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28655#M4893</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T06:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28656#M4894</link>
      <description>&lt;P&gt;hit win-r enter cmd enter cd %SPLUNK_HOME%\bin enter splunk.exe restart enter &amp;lt;done&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 06:51:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28656#M4894</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-04-17T06:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28657#M4895</link>
      <description>&lt;P&gt;take any cmd (running or not) change dir (eq cd) into your splunk installation directory, change there into bin directory, enter there the following command \"splunk.exe restart\" without the quotes!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 07:03:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28657#M4895</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-04-17T07:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28658#M4896</link>
      <description>&lt;P&gt;cd %SPLUNK_HOME%bin resulted in path cannot be found,so i entered cd Splunk then cd bin then enter splunk.exe restart enter &lt;DONE&gt;&lt;/DONE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 07:07:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28658#M4896</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T07:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28659#M4897</link>
      <description>&lt;P&gt;misteryuku,&lt;/P&gt;

&lt;P&gt;What does your Splunk architecture consist of? - i.e. is it single installation running on one PC (e.g. your laptop or PC), or is Splunk running in a networked server and you are trying to collect data from a remote PC/laptop that runs Windows 7?&lt;/P&gt;

&lt;P&gt;If you are running the Splunk server on your local PC/laptop AND the wireshark file is on the same physical machine, you will not need a forwarder (I think this may be were your confusion is) - A forwarder is used to collect data from a remote machine (i.e. if the wireshark file is on ANOTHER PC/laptop).&lt;/P&gt;

&lt;P&gt;If the wireshark file is on another machine you will need to install Splunk there as a forwarder. In which case, once you have set up the remote instance of Splunk you will probably not need to use the GUI, so it may be beneficial (for system resources (i.e. CPU, memory, etc), to disable the interface.&lt;/P&gt;

&lt;P&gt;It really depends what your architecure is ...?&lt;/P&gt;

&lt;P&gt;Regards,&lt;/P&gt;

&lt;P&gt;MHibbin&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 07:40:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28659#M4897</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-04-17T07:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28660#M4898</link>
      <description>&lt;P&gt;It is a single installation running on one PC. eg my laptop. My aim is to monintoring a converted wireshark file as a txt file using splunk. My wireshark file is found locally on my PC and the Splunk is also found in the same local PC as well. My PC is running Windows 7&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 07:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28660#M4898</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T07:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28661#M4899</link>
      <description>&lt;P&gt;Since if the wireshark file is on the same machine as Splunk, What is the way to monitor the wireshark file in txt file format instead of using forwarders?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 07:50:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28661#M4899</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T07:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28662#M4900</link>
      <description>&lt;P&gt;OK, I thought that was the situation. In that case you will not need a forwarder, so DON'T turn off the GUI!&lt;/P&gt;

&lt;P&gt;If the wireshark file is simply stored as a rolling text file (i.e. more data is appended to file, and not stored in a new file). I would set the input up as a "file monitor". The best option would be to go your manager from Splunk add another input (for example: Splunk &amp;gt;&amp;gt; Manager &amp;gt;&amp;gt; Data Inputs &amp;gt;&amp;gt; Files &amp;amp; directories &amp;gt;&amp;gt; New) and then follow the use the use the "Preview data before indexing" option to browse for your file and make sure all events appear as they are supposed to...&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 08:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28662#M4900</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-04-17T08:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28663#M4901</link>
      <description>&lt;P&gt;i.e. the correct timestamp recognition is in place, and line breaking is taking place correctly. It is easier to make changes to timestamp recognition/line breaking here, as Splunk will assist in the setup (and even show you what changes are being made to the props.conf file).&lt;/P&gt;

&lt;P&gt;If this answers your question, can you mark the answer as accpeted (the tick next to my answer), as this will show others the question does not require more attention, and helps those looking for answers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 08:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28663#M4901</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-04-17T08:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28664#M4902</link>
      <description>&lt;P&gt;So basically you mean is that i can simply upload the text file manually.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 08:08:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28664#M4902</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T08:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28665#M4903</link>
      <description>&lt;P&gt;However the contents in the wireshark txt file looks like this : &lt;/P&gt;

&lt;P&gt;Frame 1: 54 bytes on wire (432 bits), 54 bytes captured (432 bits)&lt;BR /&gt;
    Arrival Time: Feb  2, 2010 22:40:36.411832000 Malay Peninsula Standard Time&lt;BR /&gt;
    Epoch Time: 1265121636.411832000 seconds&lt;BR /&gt;
    [Time delta from previous captured frame: 0.000000000 seconds]&lt;BR /&gt;
    [Time delta from previous displayed frame: 0.000000000 seconds]&lt;BR /&gt;
    [Time since reference or first frame: 0.000000000 seconds]&lt;BR /&gt;
    Frame Number: 1&lt;BR /&gt;
    Frame Length: 54 bytes (432 bits)&lt;BR /&gt;
    Capture Length: 54 bytes (432 bits)&lt;BR /&gt;
    ............ and so on.......&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 08:09:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28665#M4903</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T08:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28666#M4904</link>
      <description>&lt;P&gt;So can i use this wireshark txt file for monitoring using Splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 08:10:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28666#M4904</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T08:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28667#M4905</link>
      <description>&lt;P&gt;What are you looking to monitor in the file?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 08:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28667#M4905</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-04-17T08:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring a wireshark file using Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28668#M4906</link>
      <description>&lt;P&gt;That means i would have to specify what i would like monitor. In this case, i would like to detect log anomalies such as the occurence of Denial of Service attacks. So what do i do so that i can monitor the wireshark text file the way i want?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Apr 2012 08:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-a-wireshark-file-using-Splunk/m-p/28668#M4906</guid>
      <dc:creator>misteryuku</dc:creator>
      <dc:date>2012-04-17T08:22:08Z</dc:date>
    </item>
  </channel>
</rss>

