All Apps and Add-ons

Why is Splunk Stream 7.x not capturing localhost / loopback / 127.0.0.1?

tmuth_splunk
Splunk Employee
Splunk Employee

I was testing Splunk Stream 7.0.1 on my laptop and trying to capture network traffic going to localhost. However, I'm not seeing any data.

0 Karma
1 Solution

tmuth_splunk
Splunk Employee
Splunk Employee

What a great question! I'm glad you asked. Your answer can be found in the documentation here:
http://docs.splunk.com/Documentation/StreamApp/7.0.1/DeployStreamApp/ConfigureStreamForwarder#Enabli...

View solution in original post

0 Karma

nathan_zhang
Engager

Hello,
I am using Splunk Stream to get Oracle stream data. I have configured loopback as documented but I can find Oracle local stream:

[root@dev local]# cat streamfwd.conf
[streamfwd]
tcpServer.N.address = 192.168.253.141
streamfwdcapture.0.interface = lo
tcpServer.N.port = 1521
streamfwdcapture.0.filter = tcp port 1521

Anyone can give some help? Thanks

0 Karma

tmuth_splunk
Splunk Employee
Splunk Employee

What a great question! I'm glad you asked. Your answer can be found in the documentation here:
http://docs.splunk.com/Documentation/StreamApp/7.0.1/DeployStreamApp/ConfigureStreamForwarder#Enabli...

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...