<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Stream App - Ingest Pcap issue in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481081#M7729</link>
    <description>&lt;P&gt;I installed Splunk Stream App and i try to ingest a pcap file into Splunk.&lt;/P&gt;

&lt;P&gt;Specifically i select: Settings &amp;gt; Data Inputs &amp;gt; Pcap Files: Add New&lt;/P&gt;

&lt;P&gt;Then i fill-in the required information as prompted by Splunk guide here: &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoparsePCAPfiles"&gt;https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoparsePCAPfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and click Next. I can see the file being loaded for a few seconds, but then nothing happens. I can;'t continue to the 2nd and last step of the uploading process "Done".&lt;/P&gt;

&lt;P&gt;streamfwd.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[streamfwd]
streamfwdcapture.0.offline = true
streamfwdcapture.0.interface = /path/to/pcap/testbed-13jun.pcap
streamfwdcapture.0.repeat = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What am i doing wrong? Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jan 2020 12:03:25 GMT</pubDate>
    <dc:creator>psychogyiokosta</dc:creator>
    <dc:date>2020-01-09T12:03:25Z</dc:date>
    <item>
      <title>Splunk Stream App - Ingest Pcap issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481081#M7729</link>
      <description>&lt;P&gt;I installed Splunk Stream App and i try to ingest a pcap file into Splunk.&lt;/P&gt;

&lt;P&gt;Specifically i select: Settings &amp;gt; Data Inputs &amp;gt; Pcap Files: Add New&lt;/P&gt;

&lt;P&gt;Then i fill-in the required information as prompted by Splunk guide here: &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoparsePCAPfiles"&gt;https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoparsePCAPfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and click Next. I can see the file being loaded for a few seconds, but then nothing happens. I can;'t continue to the 2nd and last step of the uploading process "Done".&lt;/P&gt;

&lt;P&gt;streamfwd.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[streamfwd]
streamfwdcapture.0.offline = true
streamfwdcapture.0.interface = /path/to/pcap/testbed-13jun.pcap
streamfwdcapture.0.repeat = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What am i doing wrong? Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 12:03:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481081#M7729</guid>
      <dc:creator>psychogyiokosta</dc:creator>
      <dc:date>2020-01-09T12:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App - Ingest Pcap issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481082#M7730</link>
      <description>&lt;P&gt;You are trying to upload the .pcap file or .cap file? In which Splunk version and Stream version you are facing an issue ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 13:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481082#M7730</guid>
      <dc:creator>uagrawal_splunk</dc:creator>
      <dc:date>2020-01-09T13:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App - Ingest Pcap issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481083#M7731</link>
      <description>&lt;P&gt;hello, i am using Splunk Enterprise 8.0.0 &amp;amp; Splunk Stream 7.2.0 and i am trying to upload/index a .pcap file yes.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 13:20:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481083#M7731</guid>
      <dc:creator>psychogyiokosta</dc:creator>
      <dc:date>2020-01-09T13:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App - Ingest Pcap issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481084#M7732</link>
      <description>&lt;P&gt;I came across one known issue of uploading the pcap files from UI: &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.2.0/ReleaseNotes/Knownissues" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.2.0/ReleaseNotes/Knownissues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can try the following command:&lt;/P&gt;

&lt;P&gt;./streamfwd -r pcap_file_path&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:34:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481084#M7732</guid>
      <dc:creator>uagrawal_splunk</dc:creator>
      <dc:date>2020-09-30T03:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream App - Ingest Pcap issue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481085#M7733</link>
      <description>&lt;P&gt;I believe this issue is related to mine:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/665596/splunk-stream-app-uploading-a-large-pcap-file-fail.html"&gt;https://answers.splunk.com/answers/665596/splunk-stream-app-uploading-a-large-pcap-file-fail.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Looks like when uploading a large pcap with the UI option, it fails. I need to try with CLI commands as you suggest. I will update as soon as i can. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 13:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Stream-App-Ingest-Pcap-issue/m-p/481085#M7733</guid>
      <dc:creator>psychogyiokosta</dc:creator>
      <dc:date>2020-01-10T13:28:27Z</dc:date>
    </item>
  </channel>
</rss>

