All Apps and Add-ons

Stream App: Where does the streamfwd do with the .cap data once it successfully executed?

Path Finder

I have successfully ran the command ./streamfwd against a .cap file but I am not sure where the streamfwd indexed the data too.

I have not changed the default index in stream of the forwarder. So my question is where does streamfwd store the with the data once ./streamfwd runs through the .cap file?

I have looked through all the indexes and their is no data anywhere.

Tags (2)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

The streamfwd command line executable sends events from pcap files to the Wire Data modular input (provided by the Splunk_TA_stream app) via TCP port 8889. You should run this on the same machine that has the wire data input running; either your splunk server for single-server deployment, or a universal forwarder with Splunk_TA_stream enabled. You can also forward the events to a remote server or alternate port using the -s command line option (the default is localhost, port 8889).

View solution in original post

0 Karma

Splunk Employee
Splunk Employee

The streamfwd command line executable sends events from pcap files to the Wire Data modular input (provided by the Splunk_TA_stream app) via TCP port 8889. You should run this on the same machine that has the wire data input running; either your splunk server for single-server deployment, or a universal forwarder with Splunk_TA_stream enabled. You can also forward the events to a remote server or alternate port using the -s command line option (the default is localhost, port 8889).

View solution in original post

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!