All Apps and Add-ons

streamfwd is taking systime and not pcap time

sebastianstruwe
Explorer

Hi splunkers,

I'm trying to add a pcap file via command line:

./streamfwd -b 10000000 -r /tmp/tcpdump.pcap -s http://localhost:8889 

Everything works fine, but the timestamps of the packets is the time point when the streamfwd sends the packets to the splunk instance. But it should be the timestamp of the packet itselfs (capture time point).

I'm not using the -systime option.

Best regards,
Sebastian

Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.