Getting Data In

Why is stream:http not showing

mchlbooth
New Member

I'm very new too splunk and using the botsv1-attack-only file to begin learning, please be gentle.

When I do an initial search with index="botsv1" imreallynotbatman.com the sourcetype is only showing two values of data-2 and botsv1_data_set/var/lib/splunk/botsv1/db/db_1470868141_1470799731_28/rawdata/journal. I'm not seeing results for the splunk add-ons such as stream and suricata. When sourcetype="stream:http" is added to the search no events are returned. I have no idea why this is happening. The search is set to All time and verbose mode.

Many thanks in advance.

0 Karma

pizzadudehd
New Member

I am having the same issue, were you able to find the solution to this. @mchlbooth 

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...