All Apps and Add-ons

Stream App: Where does the streamfwd do with the .cap data once it successfully executed?

w0lverineNOP
Path Finder

I have successfully ran the command ./streamfwd against a .cap file but I am not sure where the streamfwd indexed the data too.

I have not changed the default index in stream of the forwarder. So my question is where does streamfwd store the with the data once ./streamfwd runs through the .cap file?

I have looked through all the indexes and their is no data anywhere.

Tags (2)
0 Karma
1 Solution

mdickey_splunk
Splunk Employee
Splunk Employee

The streamfwd command line executable sends events from pcap files to the Wire Data modular input (provided by the Splunk_TA_stream app) via TCP port 8889. You should run this on the same machine that has the wire data input running; either your splunk server for single-server deployment, or a universal forwarder with Splunk_TA_stream enabled. You can also forward the events to a remote server or alternate port using the -s command line option (the default is localhost, port 8889).

View solution in original post

0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

The streamfwd command line executable sends events from pcap files to the Wire Data modular input (provided by the Splunk_TA_stream app) via TCP port 8889. You should run this on the same machine that has the wire data input running; either your splunk server for single-server deployment, or a universal forwarder with Splunk_TA_stream enabled. You can also forward the events to a remote server or alternate port using the -s command line option (the default is localhost, port 8889).

0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...