My understanding is that the pcap file upload via the Splunk Stream Web UI might have caused some kind of corruption. This may not be the right solution. However, this is a workaround that worked for me.
1. delete the (growing) inputs.conf file (which apparently contains some binary data)
2. delete the corresponding "data input" created via Splunk Web UI
Now, as per option 2 in manual, run the command via CLI which should be something like this:
./streamfwd -r
This should successfully cause the pcap file to be ingested by Splunk.
... View more