All Apps and Add-ons

Splunk App for Stream: Why am I getting "stream.NetworkCapture - SnifferReactor unrecognized link layer for device : 12"

splunkuser20190
New Member

When I am trying to capture a openvpn device which name is tun0, I got some error as bellow.
Logs:
2019-01-09 21:43:03 ERROR 139638504761088 stream.NetworkCapture - SnifferReactor unrecognized link layer for device : 12
2019-01-09 21:43:03 FATAL 139638504761088 stream.CaptureServer - SnifferReactor was unable to start packet capturesniffer
2019-01-09 21:44:44 WARN 139638487975680 stream.CaptureServer - No streams are configured

local/streamfwd.conf

[streamfwd]
streamfwdcapture.0.interface = tun0
streamfwdcapture.0.offline = false

Tags (1)
0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

Stream doesn't support openvpn's link layer type, so it'd be an enhancement request.

View solution in original post

0 Karma

vshcherbakov_sp
Splunk Employee
Splunk Employee

Stream doesn't support openvpn's link layer type, so it'd be an enhancement request.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...