All Apps and Add-ons

Having Problems configuring File Server Mount Points for Splunk Streams

davidwaugh
Path Finder

Hello I have Splunk Streams installed on a Centos 6 Server which is also acting as a NFS Server. This is capturing packets and writing pcaps to the correct directory.

I have a Windows Search head where I have installed the Splunk Streams App. I am trying to download pcaps from the Search Head but hitting a problem.

Under windows I have the NFS Share which stores the Pcaps mounted as my S:\ drive.

When I look under the S:\ drive I can see folders arranged by date order with subfolders which contain the pcaps.

Under App:Splunk Stream ->Confgiuration I have:
FileSever X.X.X.X:/Splunkstream
Mount Point: S:\

However when I try and download a PCAP from the search head I get the error:

Unable to download PCAP file
The configured mount point (S:) for file serverX.X.X.X:/SplunkStream does not exist.
You can edit the configured value if it is incorrect.
Read more about Targeted Packet Capture

Any ideas?

0 Karma
1 Solution

davidwaugh
Path Finder

I'm not sure If I'm allowed to answer my own question, but the solution was to have the mount point written as the a UNC path.

So rather than S:\
it was: \x.x.x.x\var\nfsshares\SplunkStream

where x.x.x.x is the IP of the remote server hosting the NFS Share.

View solution in original post

0 Karma

davidwaugh
Path Finder

I'm not sure If I'm allowed to answer my own question, but the solution was to have the mount point written as the a UNC path.

So rather than S:\
it was: \x.x.x.x\var\nfsshares\SplunkStream

where x.x.x.x is the IP of the remote server hosting the NFS Share.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...