All Apps and Add-ons

Stream App: Where does the streamfwd do with the .cap data once it successfully executed?

w0lverineNOP
Path Finder

I have successfully ran the command ./streamfwd against a .cap file but I am not sure where the streamfwd indexed the data too.

I have not changed the default index in stream of the forwarder. So my question is where does streamfwd store the with the data once ./streamfwd runs through the .cap file?

I have looked through all the indexes and their is no data anywhere.

Tags (2)
0 Karma
1 Solution

mdickey_splunk
Splunk Employee
Splunk Employee

The streamfwd command line executable sends events from pcap files to the Wire Data modular input (provided by the Splunk_TA_stream app) via TCP port 8889. You should run this on the same machine that has the wire data input running; either your splunk server for single-server deployment, or a universal forwarder with Splunk_TA_stream enabled. You can also forward the events to a remote server or alternate port using the -s command line option (the default is localhost, port 8889).

View solution in original post

0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

The streamfwd command line executable sends events from pcap files to the Wire Data modular input (provided by the Splunk_TA_stream app) via TCP port 8889. You should run this on the same machine that has the wire data input running; either your splunk server for single-server deployment, or a universal forwarder with Splunk_TA_stream enabled. You can also forward the events to a remote server or alternate port using the -s command line option (the default is localhost, port 8889).

0 Karma
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...