All Apps and Add-ons

Having Problems configuring File Server Mount Points for Splunk Streams

davidwaugh
Path Finder

Hello I have Splunk Streams installed on a Centos 6 Server which is also acting as a NFS Server. This is capturing packets and writing pcaps to the correct directory.

I have a Windows Search head where I have installed the Splunk Streams App. I am trying to download pcaps from the Search Head but hitting a problem.

Under windows I have the NFS Share which stores the Pcaps mounted as my S:\ drive.

When I look under the S:\ drive I can see folders arranged by date order with subfolders which contain the pcaps.

Under App:Splunk Stream ->Confgiuration I have:
FileSever X.X.X.X:/Splunkstream
Mount Point: S:\

However when I try and download a PCAP from the search head I get the error:

Unable to download PCAP file
The configured mount point (S:) for file serverX.X.X.X:/SplunkStream does not exist.
You can edit the configured value if it is incorrect.
Read more about Targeted Packet Capture

Any ideas?

0 Karma
1 Solution

davidwaugh
Path Finder

I'm not sure If I'm allowed to answer my own question, but the solution was to have the mount point written as the a UNC path.

So rather than S:\
it was: \x.x.x.x\var\nfsshares\SplunkStream

where x.x.x.x is the IP of the remote server hosting the NFS Share.

View solution in original post

0 Karma

davidwaugh
Path Finder

I'm not sure If I'm allowed to answer my own question, but the solution was to have the mount point written as the a UNC path.

So rather than S:\
it was: \x.x.x.x\var\nfsshares\SplunkStream

where x.x.x.x is the IP of the remote server hosting the NFS Share.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...