Hi,
We've just installed this app, and while the nfcapd is receiving flows (confirmed via tcpdump), the nfdump.log file remains empty. There are a growing number of nfcapd.* files in the nfcapd folder.
The following gets logged by nfdump.py in Splunk:
Return code =
Error: nfdump ran unsuccessfully.
Running CentOS 2.6.32-220.13.1.el6.x86_64 #1 SMP Tue Apr 17 23:56:34 BST 2012 x86_64 x86_64 x86_64 GNU/Linux
Splunk 4.3.2, build 123586 (running as splunk user)
Thanks
Unfortunately I have no update on this; we’re using NfSen as we couldn’t get the Splunk app working reliably.
Still nothing on this? I have the same problem as well, CentOS 64-Bit.
Hello,
I have got the same problem.
Any thoughts?
Regards