All Apps and Add-ons

Looking for ICMP in Stream?

AzJimbo
Path Finder

Trying to see if I can get ICMP in Stream. Any suggestions? Don't want to go the pdml parser route if I can tease it out of already installed Stream app.

Tags (1)
1 Solution

mdickey_splunk
Splunk Employee
Splunk Employee

ICMP is not currently supported by stream; however, it is on our list of protocols to add for a future release.

View solution in original post

dcavuto_splunk
Splunk Employee
Splunk Employee

It's a good point, AzJimbo. I'm the new Product Manager for Stream, and I appreciate your feedback!

I'll take a look at the backlog and see if we can prioritize ICMP in an upcoming Stream release.

Thanks!
-David

AzJimbo
Path Finder

Awesome! Stream app 6.6.0 now has ICMP. Thank you.

0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

ICMP is not currently supported by stream; however, it is on our list of protocols to add for a future release.

AzJimbo
Path Finder

Thanks- I'm look to use it to enhance security analysis.

0 Karma

AzJimbo
Path Finder

Sooooo..... it's been a couple of years; but I still don't see ICMP in the Stream App? I'm currently running nfdump just so I can get the ICMP, but would much rather use just the Stream app. Looking to detect and alert on icmp tunneling, a method to stealthy exfil data out of a compromised network. (http://www.cs.uit.no/~daniels/PingTunnel/) .

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...