<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Nature of traffic in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Nature-of-traffic/m-p/540508#M152919</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two instances of Asterisk running in my production environment. The third server has a Splunk indexer installed with Universal Forwarders installed on the two Asterisk servers, respectively. The calling system is via SIP trunks and all of the calls fall on the Asterisk servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I would like to monitor the nature of the traffic that is catered by the Asterisk Servers, i.e. UDP, TCP or RTP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to do so?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any degree of help will be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks and regards,&lt;/P&gt;&lt;P&gt;Hisham&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2021 12:20:37 GMT</pubDate>
    <dc:creator>hishamjan</dc:creator>
    <dc:date>2021-02-19T12:20:37Z</dc:date>
    <item>
      <title>Nature of traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Nature-of-traffic/m-p/540508#M152919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two instances of Asterisk running in my production environment. The third server has a Splunk indexer installed with Universal Forwarders installed on the two Asterisk servers, respectively. The calling system is via SIP trunks and all of the calls fall on the Asterisk servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I would like to monitor the nature of the traffic that is catered by the Asterisk Servers, i.e. UDP, TCP or RTP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to do so?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any degree of help will be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks and regards,&lt;/P&gt;&lt;P&gt;Hisham&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 12:20:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Nature-of-traffic/m-p/540508#M152919</guid>
      <dc:creator>hishamjan</dc:creator>
      <dc:date>2021-02-19T12:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Nature of traffic</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Nature-of-traffic/m-p/540669#M152970</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228379"&gt;@hishamjan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;RTP and SIP are application layer protocols that may use either TCP or UDP as a transport. I'm not familiar with Asterisk, but it presumably includes functionality to log session and call metrics.&lt;/P&gt;&lt;P&gt;You can use &lt;A href="https://splunkbase.splunk.com/app/1809/" target="_self"&gt;Splunk App for Stream&lt;/A&gt; to monitor network traffic on the forwarders and send cooked traffic events to the indexer. Both RTP and SIP are &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/VoIP" target="_self"&gt;supported&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;The implementation of Splunk App for Stream can be non-trivial. If you're unfamiliar with packet capture and protocol analysis concepts, you may prefer to enlist Splunk Professional Services or another qualified consultant.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 21:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Nature-of-traffic/m-p/540669#M152970</guid>
      <dc:creator>tscroggins</dc:creator>
      <dc:date>2021-02-20T21:25:06Z</dc:date>
    </item>
  </channel>
</rss>

