i have created a index for testing and selected that when i ingest the pcap. also i have selected system time. All that happens is that the inputs.conf file has the content of the pcap. I cannot see any data actually in splunk.
... View more
has it made your inputs.conf file really big?
I am having the same issue. Each time i add a pcap it seems to complain and if i look on my search head under etc\system\local the inputs file will contain the pcap data. Not sure that's right as it could potentially fill up the search heads drive
Damain
... View more