All Apps and Add-ons

Why is the Splunk App for Stream 6.4.1 unable to see HTTP stream data?

todd_miller
Communicator

Running Splunk 6.3.1 and Splunk App for Stream 6.4.1. I have a Linux box running the Stream TA. This box is pulling data on an interface connected to a tap. A tcpdump on the box is showing HTTP traffic, however, I'm not seeing any HTTP streams in the Splunk App for Stream. I have no filters configured so I'm assuming it should be collecting all network data. I can confirm that I'm seeing various other data being ingested into my instance: DNS, SMB, TCP, UDP, etc. I'm also seeing TCP data destined for port 80.

Why would the Splunk App for Stream be unable to see the HTTP data?

Tags (2)

vshcherbakov_sp
Splunk Employee
Splunk Employee

hi todd_miller,

A couple of things to check:
- make sure that HTTP-based streams - http, Splunk_HTTP*, your custom HTTP streams (if any) are created and enabled in the App For Stream UI->Configuration->Configure Streams
- check that these streams are configured for the stream forwarder group(s) your Stream TA belongs to ( Configuration -> Distributed Forwarder Management)

0 Karma

todd_miller
Communicator

Sorry this took so long to get back to you.

I did check that all streams relating to HTTP are enabled and I also checked to make sure that the streams are configured for the stream forwarder groups.

This is a very simple config of one stream forwarder sending all stream traffic to my splunk server.

I also verified that traffic destined to port 80 is being indexed. The application is listed as "Unknown".

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

If the traffic is being indexed as "Unknown" (app="unknown", correct?) it looks like Stream fails to classify it as HTTP, which is kind of odd... Is your traffic by any chance HTTP/2, or encrypted with SSL/TLS, or somehow encapsulated? Would you be able to open a support case and supply a sample tcpdump capture of it?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...