Getting Data In

How to make a script.

sincerus
New Member

Dear All,

I hope you can help me with the next problem:

I cant virtualize a tcpdump on my mac.
I wish to get some information on en0, this means i need to change eth0 to en0.
At this moment i have 0 events, and when i clone this script its not placed for SplunkViz but launcer.

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh eth1 should be :

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh en0

For some clearence:
Everything that will be going trough my ethernet port ( en0) i would like to see in my SplunkViz.

Any idea what i do wrong ?

Tags (2)
0 Karma

sincerus
New Member

I am using this tool by the way :

http://metasplunk.com/projects/particle

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Introducing .conf Stories Series!

“.conf Stories” Series – First Feature: Rich Mahlerwein   Every year .conf brings together some of the most ...