All Apps and Add-ons

Splunk App for Stream: Where can I find a complete list of protocols automatically detected in the "app" field of stream:tcp?

kwchang_splunk
Splunk Employee
Splunk Employee

Hello,

As described in the following stream product document, the 'app' field of stream:tcp has the detected protocol name automatically, like "tor", "bittorent" or "skype".
http://docs.splunk.com/Documentation/StreamApp/6.4.0/DeployStreamApp/Whattypeofdatadoesthisappcollec...

BTW, where can I find the complete list of the protocols which can be detected automatically?

Thank you in advance.

Tags (1)
0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hi kwchang,

I created a ticket to properly document the list of classified protocols; meanwhile please find the preliminary list below (please keep in mind that it's preliminary and subject to change, etc.):

8021q
aim
amqp
bgp
bittorrent
cotp
db2
dcerpc
dhcp
diameter
dns
drda
ftp
gmail
google_gen
gre
http
https
http_tunnel
ica
imap
informix
ipx
irc
iscsi
jabber
krb5
ldap
llc
mapi
mcs
mq
msn
msrpc
mount
mysql
netbios
netflow
nfs
pop3
postgres
radius
rdp
rip1
rip2
rpc
rtp
sip
skype
smb
smpp
smtp
sna
snmp
socks4
socks5
ssh
ssl
stun
syslog
tcp
tds
telnet
tftp
tns
tor
udp
wins

View solution in original post

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hi kwchang,

I created a ticket to properly document the list of classified protocols; meanwhile please find the preliminary list below (please keep in mind that it's preliminary and subject to change, etc.):

8021q
aim
amqp
bgp
bittorrent
cotp
db2
dcerpc
dhcp
diameter
dns
drda
ftp
gmail
google_gen
gre
http
https
http_tunnel
ica
imap
informix
ipx
irc
iscsi
jabber
krb5
ldap
llc
mapi
mcs
mq
msn
msrpc
mount
mysql
netbios
netflow
nfs
pop3
postgres
radius
rdp
rip1
rip2
rpc
rtp
sip
skype
smb
smpp
smtp
sna
snmp
socks4
socks5
ssh
ssl
stun
syslog
tcp
tds
telnet
tftp
tns
tor
udp
wins

kwchang_splunk
Splunk Employee
Splunk Employee

Thank you.

0 Karma

kwchang_splunk
Splunk Employee
Splunk Employee

It would be good if the document will contain short descriptions about the each of those and also about the related protocol parsers which we can use for parsing it with (if app=jabber, we can use XMPP for parsing the details).

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...