<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: App for Stream - pcap replay in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123598#M184212</link>
    <description>&lt;P&gt;Should work.  There's a long list of questions about your environment we need to ask to help troubleshoot.  Given the amount of detailed work that needs to happen, support is probably a better option than Answers.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Sep 2014 17:46:12 GMT</pubDate>
    <dc:creator>csharp_splunk</dc:creator>
    <dc:date>2014-09-15T17:46:12Z</dc:date>
    <item>
      <title>App for Stream - pcap replay</title>
      <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123595#M184209</link>
      <description>&lt;P&gt;I have a pcap with DNS traffic that I want to analyze. I downloaded the 'Stream Examples' app and the main Splunk App for Stream. There is a Stream Replay input option which I pointed at my .pcap but I don't see any data. I have the 'streamfwd' enabled and I don't see any data related to that either. I followed the Install guide for all this so I am not sure what else to do here.&lt;/P&gt;

&lt;P&gt;Any help or troubleshooting options would be helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2014 20:41:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123595#M184209</guid>
      <dc:creator>sswansonchtr</dc:creator>
      <dc:date>2014-09-12T20:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: App for Stream - pcap replay</title>
      <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123596#M184210</link>
      <description>&lt;P&gt;What operating system are you running?&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2014 19:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123596#M184210</guid>
      <dc:creator>csharp_splunk</dc:creator>
      <dc:date>2014-09-14T19:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: App for Stream - pcap replay</title>
      <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123597#M184211</link>
      <description>&lt;P&gt;Red Hat Enterprise Linux Server release 5.7 (Tikanga)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2014 15:57:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123597#M184211</guid>
      <dc:creator>sswansonchtr</dc:creator>
      <dc:date>2014-09-15T15:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: App for Stream - pcap replay</title>
      <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123598#M184212</link>
      <description>&lt;P&gt;Should work.  There's a long list of questions about your environment we need to ask to help troubleshoot.  Given the amount of detailed work that needs to happen, support is probably a better option than Answers.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2014 17:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123598#M184212</guid>
      <dc:creator>csharp_splunk</dc:creator>
      <dc:date>2014-09-15T17:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: App for Stream - pcap replay</title>
      <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123599#M184213</link>
      <description>&lt;P&gt;I will contact support. The environment is straightforward VM install with a base splunk install I use for importing logs to troubleshoot.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2014 21:11:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123599#M184213</guid>
      <dc:creator>sswansonchtr</dc:creator>
      <dc:date>2014-09-15T21:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: App for Stream - pcap replay</title>
      <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123600#M184214</link>
      <description>&lt;P&gt;What link layer your pcap file has? App for Stream only support ethernet, linux cooked sockets and DLT_NULL link types. Wireshark should be able to tell you the link type; you may also want to look for "SnifferReactor unrecognized link layer for device " error messages in the streamfwd.log file&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 00:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123600#M184214</guid>
      <dc:creator>vshcherbakov_sp</dc:creator>
      <dc:date>2015-02-12T00:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: App for Stream - pcap replay</title>
      <link>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123601#M184215</link>
      <description>&lt;P&gt;Were you able to edit the streamfwd.xml config file in the local directory for your Splunk Stream instance? Check out this link, it goes over setting up Splunk Stream to look at a specific PCAP file : &lt;A href="+https://answers.splunk.com/answers/220040/running-stream-against-old-pcaps.html"&gt;https://answers.splunk.com/answers/220040/running-stream-against-old-pcaps.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I hope that helps!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 21:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/App-for-Stream-pcap-replay/m-p/123601#M184215</guid>
      <dc:creator>amiracle</dc:creator>
      <dc:date>2016-01-14T21:13:14Z</dc:date>
    </item>
  </channel>
</rss>

