Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Stream is not capture interfaces

$
0
0
Hi, I install stream-app on Splunk Search-Head and deploy independent Stream forwarder via `"curl -sSL http://stream-cont-func02:8000/en-us/custom/splunk_app_stream/install_streamfwd | sudo bash"` command. I enabled HEC. I check the stream-app GUI, server status is active and send metadata. I mirror the traffic from switch to server interface and check the interface via tcpdump command. I see the traffics are mirrored. But I can not see the traffics int the splunk stream app. Splunk says normally splunk streamfwd capture all network interfaces. What can I do? Best Regards Thank you

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>