Getting Data In

How to make a script.

sincerus
New Member

Dear All,

I hope you can help me with the next problem:

I cant virtualize a tcpdump on my mac.
I wish to get some information on en0, this means i need to change eth0 to en0.
At this moment i have 0 events, and when i clone this script its not placed for SplunkViz but launcer.

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh eth1 should be :

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh en0

For some clearence:
Everything that will be going trough my ethernet port ( en0) i would like to see in my SplunkViz.

Any idea what i do wrong ?

Tags (2)
0 Karma

sincerus
New Member

I am using this tool by the way :

http://metasplunk.com/projects/particle

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...