Dear All,
I hope you can help me with the next problem:
I cant virtualize a tcpdump on my mac.
I wish to get some information on en0, this means i need to change eth0 to en0.
At this moment i have 0 events, and when i clone this script its not placed for SplunkViz but launcer.
/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh eth1 should be :
/Applications/Splunk/etc/apps/SplunkViz/bin/capture_tcpdump.sh en0
For some clearence:
Everything that will be going trough my ethernet port ( en0) i would like to see in my SplunkViz.
Any idea what i do wrong ?
I am using this tool by the way :