Getting Data In

How to make a script.

sincerus
New Member

Dear All,

I hope you can help me with the next problem:

I cant virtualize a tcpdump on my mac.
I wish to get some information on en0, this means i need to change eth0 to en0.
At this moment i have 0 events, and when i clone this script its not placed for SplunkViz but launcer.

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh eth1 should be :

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh en0

For some clearence:
Everything that will be going trough my ethernet port ( en0) i would like to see in my SplunkViz.

Any idea what i do wrong ?

Tags (2)
0 Karma

sincerus
New Member

I am using this tool by the way :

http://metasplunk.com/projects/particle

0 Karma
Get Updates on the Splunk Community!

Extending Splunk AI Assistant for SPL to Splunk Enterprise customers!

Howdy Splunk Community! It’s an exciting day here at Splunk – Splunk AI Assistant for SPL version 1.3.0 is now ...

Developer Spotlight with Qmulos

Qmulos: Building a Next-Level Cybersecurity Business through Splunk Apps Qmulos started as a scrappy startup ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...