I am having issues ingesting PCAP files from the GUI.
I found similar Answers and bug "STREAM-4235" but it appears to be resolved in Stream v7.3 which I am currently using.
I have tried Splunk Enterprise 8.0.5 and 8.1.2
I tried following this documentation: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/UseStreamtoparsePCAPfiles
Per its instructions, I downloaded these apps:
https://splunkbase.splunk.com/app/1809/
https://splunkbase.splunk.com/app/5238/ (Splunk_TA_stream seems to be "Splunk Add-on for Stream Forwarders")
From Splunk 8.0.5 I get an attribute error. I am assuming there is a compatibility issue.
No errors from Splunk 8.1.2, but the files were no where to be found without any good indication of what happened in the logs.
I tested the servers ability to collect and index data into the target index via the collect command with no issues.
On one of my test servers, I ran through the inputs.conf and "set_permissions.sh" steps found here. It did more than what I wanted and didn't help: here: https://docs.splunk.com/Documentation/StreamApp/7.3.0/DeployStreamApp/InstallStreamForwarder