All Apps and Add-ons

Looking for ICMP in Stream?

AzJimbo
Path Finder

Trying to see if I can get ICMP in Stream. Any suggestions? Don't want to go the pdml parser route if I can tease it out of already installed Stream app.

Tags (1)
1 Solution

mdickey_splunk
Splunk Employee
Splunk Employee

ICMP is not currently supported by stream; however, it is on our list of protocols to add for a future release.

View solution in original post

dcavuto_splunk
Splunk Employee
Splunk Employee

It's a good point, AzJimbo. I'm the new Product Manager for Stream, and I appreciate your feedback!

I'll take a look at the backlog and see if we can prioritize ICMP in an upcoming Stream release.

Thanks!
-David

AzJimbo
Path Finder

Awesome! Stream app 6.6.0 now has ICMP. Thank you.

0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

ICMP is not currently supported by stream; however, it is on our list of protocols to add for a future release.

AzJimbo
Path Finder

Thanks- I'm look to use it to enhance security analysis.

0 Karma

AzJimbo
Path Finder

Sooooo..... it's been a couple of years; but I still don't see ICMP in the Stream App? I'm currently running nfdump just so I can get the ICMP, but would much rather use just the Stream app. Looking to detect and alert on icmp tunneling, a method to stealthy exfil data out of a compromised network. (http://www.cs.uit.no/~daniels/PingTunnel/) .

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...