Splunk Enterprise Security

Splunk Stream ingest PCAP from the GUI issue

_joe
Communicator

I am having issues ingesting PCAP files from the GUI.

I found similar Answers and bug "STREAM-4235" but it appears to be resolved in Stream v7.3 which I am currently using. 

I have tried Splunk Enterprise 8.0.5 and 8.1.2

I tried following this documentation: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/UseStreamtoparsePCAPfiles

Per its instructions, I downloaded these apps:
https://splunkbase.splunk.com/app/1809/
https://splunkbase.splunk.com/app/5238/ (Splunk_TA_stream seems to be "Splunk Add-on for Stream Forwarders")

From Splunk 8.0.5 I get an attribute error. I am assuming there is a compatibility issue.

No errors from Splunk 8.1.2, but the files were no where to be found without any good indication of what happened in the logs.

I tested the servers ability to collect and index data into the target index via the collect command with no issues.

On one of my test servers, I ran through the inputs.conf and  "set_permissions.sh" steps found here. It did more than what I wanted and didn't help: here: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/InstallStreamForwarder

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...