Splunk Enterprise Security

Splunk Stream ingest PCAP from the GUI issue

_joe
Communicator

I am having issues ingesting PCAP files from the GUI.

I found similar Answers and bug "STREAM-4235" but it appears to be resolved in Stream v7.3 which I am currently using. 

I have tried Splunk Enterprise 8.0.5 and 8.1.2

I tried following this documentation: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/UseStreamtoparsePCAPfiles

Per its instructions, I downloaded these apps:
https://splunkbase.splunk.com/app/1809/
https://splunkbase.splunk.com/app/5238/ (Splunk_TA_stream seems to be "Splunk Add-on for Stream Forwarders")

From Splunk 8.0.5 I get an attribute error. I am assuming there is a compatibility issue.

No errors from Splunk 8.1.2, but the files were no where to be found without any good indication of what happened in the logs.

I tested the servers ability to collect and index data into the target index via the collect command with no issues.

On one of my test servers, I ran through the inputs.conf and  "set_permissions.sh" steps found here. It did more than what I wanted and didn't help: here: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/InstallStreamForwarder

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...