I have Splunk up and running on a Linux system. I was able to import a PCAP file,
Import is set to /splunk_pcap, pcap fiels
and they get migrated to /opt/splunk/apps/SplunkForPCAP/PCAPConverted/.
According to the documentation when this happens the data is imported.
I can see the data sets but can't analyze older PCAP files in the app "PCAP Analyzer for Splunk"
Is there a way to set it to see all of the PCAP files in the interface?