Splunk Search

Nature of traffic

hishamjan
Explorer

Hi,

 

I have two instances of Asterisk running in my production environment. The third server has a Splunk indexer installed with Universal Forwarders installed on the two Asterisk servers, respectively. The calling system is via SIP trunks and all of the calls fall on the Asterisk servers.

 

Now, I would like to monitor the nature of the traffic that is catered by the Asterisk Servers, i.e. UDP, TCP or RTP?

 

Is there a way to do so? 

 

Any degree of help will be appreciated.

 

thanks and regards,

Hisham

Labels (7)
0 Karma

tscroggins
Influencer

@hishamjan

RTP and SIP are application layer protocols that may use either TCP or UDP as a transport. I'm not familiar with Asterisk, but it presumably includes functionality to log session and call metrics.

You can use Splunk App for Stream to monitor network traffic on the forwarders and send cooked traffic events to the indexer. Both RTP and SIP are supported.

The implementation of Splunk App for Stream can be non-trivial. If you're unfamiliar with packet capture and protocol analysis concepts, you may prefer to enlist Splunk Professional Services or another qualified consultant.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...