All Apps and Add-ons

Splunk App for Stream: about X-Forwarded-For Header

kwchang_splunk
Splunk Employee
Splunk Employee

Hello,

According to the documentation of Splunk App for Stream, 'src_ip' value should capture the 'X-Forwarded-For' header value instead of the original src_ip. But it doesn't seem to work on my instance.
As you can see from following attached image, there is a "X-Forwarded-For" header in my src_headers attribute, but the src_ip has different value.
I'm using Splunk 6.3.1 and Stream App 6.4.1.
Thank you in advance.

alt text

Tags (1)
0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi kwchang,

Seems like a bug.. would you by any chance be able to provide a sample .pcap file that exhibit this problem?

View solution in original post

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi kwchang,

Seems like a bug.. would you by any chance be able to provide a sample .pcap file that exhibit this problem?

0 Karma
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...