All Apps and Add-ons

Splunk App for Stream: Why can I only see localhost activity?

jmallorquin
Builder

Hi,

I have installed the app Streams on Splunk 6.1.3 with Centos 64, everything looks like the app is working but i can only see the activity of localhost.
I have checked the filters and there isn't any filter.
The TA and the APP are in the same server (indexer).

Anyone knows what could be happening?

Thanks,

Tags (2)

mdickey_splunk
Splunk Employee
Splunk Employee

App for Stream can only see traffic for the network devices available on the same host machine. You may want to try using the <Interface> or <InterfaceRegex> configuration parameters in streamfwd.xml to make sure it's capturing traffic from all of the available devices. See "Use XML Capture element to specify network interfaces" for more information.

0 Karma

jmallorquin
Builder

Thanks neelamssntosh but the problem is that I would like to that app hear all the traffic not only the one that generate the host.

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Community Content Calendar, October Edition

Welcome to the October edition of our Community Spotlight! The Splunk Community is a treasure trove of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...