All Apps and Add-ons

Can the Splunk App for Stream extract payload data?

hakansel05
New Member

Hi all,

Can the Splunk App for Stream save and/or extract the payload data? If yes, how can I enable this for stream?

Thanks in advance.

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Hello,

Stream supports the generic src_content/dest_content fields that represent the "payload" data for certain protocols such as HTTP or TCP. You can also extract specific parts of these fields (or any other textual fields for that matter) with a regular expression using so called "content extraction" feature of Stream. Here's the documentation link for more details: http://docs.splunk.com/Documentation/StreamApp/6.3.2/DeployStreamApp/ConfigureStreams#Use_Content_Ex...

0 Karma

hakansel05
New Member

Thanks but, there are no fields as src_content/dest_content. Also I have analyzed at the raw stream data in event by event, there is no like that data. Is there any need to more configuration to get more detailed capturing wire data?

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

src_content/dest_content fields are available only for HTTP and TCP/UDP protocols and not enabled by default - you'll need to go to the Streams Config page and enable them. Also, there's a default field size limit of 10K that you may want to change by setting the MaxFieldSize parameter (see http://docs.splunk.com/Documentation/StreamApp/6.3.2/DeployStreamApp/ConfigureStreamForwarder#Advanc... for more details)

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...