All Apps and Add-ons

Splunk App for Stream: Why can I only see localhost activity?

jmallorquin
Builder

Hi,

I have installed the app Streams on Splunk 6.1.3 with Centos 64, everything looks like the app is working but i can only see the activity of localhost.
I have checked the filters and there isn't any filter.
The TA and the APP are in the same server (indexer).

Anyone knows what could be happening?

Thanks,

Tags (2)

mdickey_splunk
Splunk Employee
Splunk Employee

App for Stream can only see traffic for the network devices available on the same host machine. You may want to try using the <Interface> or <InterfaceRegex> configuration parameters in streamfwd.xml to make sure it's capturing traffic from all of the available devices. See "Use XML Capture element to specify network interfaces" for more information.

0 Karma

jmallorquin
Builder

Thanks neelamssntosh but the problem is that I would like to that app hear all the traffic not only the one that generate the host.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...