@FrankVl That tcpdump command is golden for troubleshooting any tcpin input. I just used it to show that Splunk was indeed receiving the data but a bad timestamp was causing the "lag". Saved this command for future troubleshooting sessions. Thanks for sharing it with us.
... View more