Splunk Search

Nature of traffic

hishamjan
Explorer

Hi,

 

I have two instances of Asterisk running in my production environment. The third server has a Splunk indexer installed with Universal Forwarders installed on the two Asterisk servers, respectively. The calling system is via SIP trunks and all of the calls fall on the Asterisk servers.

 

Now, I would like to monitor the nature of the traffic that is catered by the Asterisk Servers, i.e. UDP, TCP or RTP?

 

Is there a way to do so? 

 

Any degree of help will be appreciated.

 

thanks and regards,

Hisham

Labels (7)
0 Karma

tscroggins
Champion

@hishamjan

RTP and SIP are application layer protocols that may use either TCP or UDP as a transport. I'm not familiar with Asterisk, but it presumably includes functionality to log session and call metrics.

You can use Splunk App for Stream to monitor network traffic on the forwarders and send cooked traffic events to the indexer. Both RTP and SIP are supported.

The implementation of Splunk App for Stream can be non-trivial. If you're unfamiliar with packet capture and protocol analysis concepts, you may prefer to enlist Splunk Professional Services or another qualified consultant.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...