Splunk Enterprise Security

Splunk Stream ingest PCAP from the GUI issue

_joe
Contributor

I am having issues ingesting PCAP files from the GUI.

I found similar Answers and bug "STREAM-4235" but it appears to be resolved in Stream v7.3 which I am currently using. 

I have tried Splunk Enterprise 8.0.5 and 8.1.2

I tried following this documentation: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/UseStreamtoparsePCAPfiles

Per its instructions, I downloaded these apps:
https://splunkbase.splunk.com/app/1809/
https://splunkbase.splunk.com/app/5238/ (Splunk_TA_stream seems to be "Splunk Add-on for Stream Forwarders")

From Splunk 8.0.5 I get an attribute error. I am assuming there is a compatibility issue.

No errors from Splunk 8.1.2, but the files were no where to be found without any good indication of what happened in the logs.

I tested the servers ability to collect and index data into the target index via the collect command with no issues.

On one of my test servers, I ran through the inputs.conf and  "set_permissions.sh" steps found here. It did more than what I wanted and didn't help: here: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/InstallStreamForwarder

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...