Getting Data In

How to make a script.

sincerus
New Member

Dear All,

I hope you can help me with the next problem:

I cant virtualize a tcpdump on my mac.
I wish to get some information on en0, this means i need to change eth0 to en0.
At this moment i have 0 events, and when i clone this script its not placed for SplunkViz but launcer.

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh eth1 should be :

/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh en0

For some clearence:
Everything that will be going trough my ethernet port ( en0) i would like to see in my SplunkViz.

Any idea what i do wrong ?

Tags (2)
0 Karma

sincerus
New Member

I am using this tool by the way :

http://metasplunk.com/projects/particle

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...