- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi to everyone
I have a new Splunk instance with the Splunk App for Stream with default installation. In my machine, I have two interfaces: the first, for Internet, and the second, in promiscuous mode, with the whole network traffic (I'm sure about that, I saw it in Wireshark).
However, in Splunk App for Stream, I can only see the first interface, traffic. How can I solve this?
Thanks you very much
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hello rubeniturrieta,
you need to specify the interface you want App for Stream to capture on in etc/apps/Splunk_TA_stream/local/streamfwd.xml file. See http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/ConfigureStreamForwarder#Use_XM...
HTH
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hello rubeniturrieta,
you need to specify the interface you want App for Stream to capture on in etc/apps/Splunk_TA_stream/local/streamfwd.xml file. See http://docs.splunk.com/Documentation/StreamApp/6.3.0/DeployStreamApp/ConfigureStreamForwarder#Use_XM...
HTH
