Is there any possibility to receive attributes on which network interface and/or VLAN ID streamfwd has received a packet?
Can the reactor be customized so that it provides these and additional attributes, notably additional fields after dissecting DNS flows?
If not, can you please consider this as a feature request?
(How shall we submit submit feature requests best, not being (yet) customers with a maintenance contract?)
Sounds awesome
I think it would be good to have
- receiving interface name
- receiving port
In many cases the port might be already enough, but we have to go through a virtual interface so
The previously mentioned VLAN tags is rather something for the flow layer...
It might help if you process traffic from one network domain, but if the processed traffic originates from different networks with their own VLAN tag allocation... out of luck 🙂
Sadly we haven't done this yet. I'm looking into getting this in the next release.
Hi Splunkers
Any Update on this front?
Use Case
Im forwarding Traffic from different sources to the stream processing instance.
But I would like to later be able to distinguish the traffic from the different sources.
Solution 1 : Create for each source a separate processing instance ...
Solution 2 : Install multiple ufwd on the instance using different identifiers
Solution 3 : Process all the traffic on the same instance, but have it tagged by receiving interface name on the streamfwd.
Solution 3 would be the best.
Solution 2 might work ...
Greetings
Perfectly fine place to request features! Clayton has put this in the backlog for you, and we'll look into doing this in the next release. It's not much work, so we'll likely be able to deliver.
What additional data are you looking for from DNS?
This is not possible at this time and something we will have to do further investigation.