Getting Data In

using stream forwarder to forward pcap data

weicheng98
Path Finder

Hi, I would like to forward pcap data using tcpreplay on a remote machine which has installed a stream forwarder to forward the pcap data to my local machine. In my local machine, I have installed splunk stream but I did not receive any pcap data when I run tcpreplay on my remote machine.

e.g. I ran this on my remote machine, but it didnt worked. So I tried installing a universal forwarder.
./streamfwd -r '/root/Desktop/mypacket.pcap' -s http://:8889

e.g. using universal forwarder
sudo ./splunk add forward-server :9997

then I added the directory to monitor.
./splunk add monitor /root/Desktop -sourcetype pcap_capture -index wireshark_pcaptest
(is that how universal forwarder works like it monitors traffic in the desktop directory since im running tcpreplay on my desktop ?)

So my question is how do I receive pcap data using the both methods as mentioned above ? Because I want to simulate a real-time traffic through tcpreplay. (please correct my understanding)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...