Getting Data In

Why is stream:http not showing

mchlbooth
New Member

I'm very new too splunk and using the botsv1-attack-only file to begin learning, please be gentle.

When I do an initial search with index="botsv1" imreallynotbatman.com the sourcetype is only showing two values of data-2 and botsv1_data_set/var/lib/splunk/botsv1/db/db_1470868141_1470799731_28/rawdata/journal. I'm not seeing results for the splunk add-ons such as stream and suricata. When sourcetype="stream:http" is added to the search no events are returned. I have no idea why this is happening. The search is set to All time and verbose mode.

Many thanks in advance.

0 Karma

pizzadudehd
New Member

I am having the same issue, were you able to find the solution to this. @mchlbooth 

0 Karma
Get Updates on the Splunk Community!

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...

Stay Connected: Your Guide to August Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Unleash the Power of Splunk MCP and AI, Meet Us at .Conf 2025, and Find Even More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...