Derp nothing to see here- I used the generic data input and not the PCAP app specific app input
the PCAP Analyzer for Splunk is based on the PCAP app input, you have to define it in the UI. In the application you find a "how to get started guide".
Let me know if you have detailed questions.
View solution in original post
I had used the data inputs menu at the top of the data input webUI. I later realized I needed to scroll down and use the PCAP app specific data input menu at the bottom.
I do have a question on that, how does one make an app that adds a data input like that in the webUI? That is really really cool.