- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Stream is not capture interfaces
mesutu
Explorer
01-07-2020
02:03 AM
Hi,
I install stream-app on Splunk Search-Head and deploy independent Stream forwarder via "curl -sSL http://stream-cont-func02:8000/en-us/custom/splunk_app_stream/install_streamfwd | sudo bash"
command. I enabled HEC. I check the stream-app GUI, server status is active and send metadata.
I mirror the traffic from switch to server interface and check the interface via tcpdump command. I see the traffics are mirrored. But I can not see the traffics int the splunk stream app. Splunk says normally splunk streamfwd capture all network interfaces.
What can I do?
Best Regards
Thank you
