All Apps and Add-ons

streamfwd is taking systime and not pcap time

sebastianstruwe
Explorer

Hi splunkers,

I'm trying to add a pcap file via command line:

./streamfwd -b 10000000 -r /tmp/tcpdump.pcap -s http://localhost:8889 

Everything works fine, but the timestamps of the packets is the time point when the streamfwd sends the packets to the splunk instance. But it should be the timestamp of the packet itselfs (capture time point).

I'm not using the -systime option.

Best regards,
Sebastian

Get Updates on the Splunk Community!

New Cloud Intrusion Detection System Add-on for Splunk

In July 2022 Splunk released the Cloud IDS add-on which expanded Splunk capabilities in security and data ...

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...