- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
kwchang_splunk

Splunk Employee
11-26-2015
09:23 PM
Hello,
According to the documentation of Splunk App for Stream, 'src_ip' value should capture the 'X-Forwarded-For' header value instead of the original src_ip. But it doesn't seem to work on my instance.
As you can see from following attached image, there is a "X-Forwarded-For" header in my src_headers attribute, but the src_ip has different value.
I'm using Splunk 6.3.1 and Stream App 6.4.1.
Thank you in advance.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
vshcherbakov_sp

Splunk Employee
11-30-2015
09:45 AM
hi kwchang,
Seems like a bug.. would you by any chance be able to provide a sample .pcap file that exhibit this problem?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
vshcherbakov_sp

Splunk Employee
11-30-2015
09:45 AM
hi kwchang,
Seems like a bug.. would you by any chance be able to provide a sample .pcap file that exhibit this problem?
