Getting Data In

Why is stream:http not showing

New Member

I'm very new too splunk and using the botsv1-attack-only file to begin learning, please be gentle.

When I do an initial search with index="botsv1" the sourcetype is only showing two values of data-2 and botsv1_data_set/var/lib/splunk/botsv1/db/db_1470868141_1470799731_28/rawdata/journal. I'm not seeing results for the splunk add-ons such as stream and suricata. When sourcetype="stream:http" is added to the search no events are returned. I have no idea why this is happening. The search is set to All time and verbose mode.

Many thanks in advance.

0 Karma

New Member

I am having the same issue, were you able to find the solution to this. @mchlbooth 

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!