This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Can i use the wireshark pcap file capture data and store the data into Splunk for indexing?

asked 15 Apr '12, 18:51

misteryuku's gravatar image

misteryuku
20242630
accept rate: 0%

edited 15 Apr '12, 18:51


Probably. Using either Wireshark, or more likely tshark and setting options to output only the fields required and using a csv format the data could be fed into Splunk.

If you can explain exactly what data you wish to extract from the pcap files someone should be able to give you a recipe for doing that.

Actually getting the data into Splunk is not a suitable topic for this site though.

permanent link

answered 16 Apr '12, 00:01

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

Well, if you check on the Splunk Q&A site, that question appears to have been answered already, and the answer, sadly, is "no", as Splunk appears, at least from what one answer to that question says, to read only text files, and pcap files are NOT text files. Other answers seem to indicate that if you feed a pcap file to TShark and have it print out the file in verbose format, Splunk can read the resulting text file.

permanent link

answered 16 Apr '12, 01:00

Guy%20Harris's gravatar image

Guy Harris ♦♦
17.4k335196
accept rate: 19%

So the way is to convert the pcap to a csv file using tshark commands is that right???

(16 Apr '12, 01:25) misteryuku

In the answer on the Splunk Q&A site, they converted it to a human-readable display of the full protocol tree, not a CSV file. If you want further help in getting Splunk to process a pcap file, the best place to ask is on the Spunk Q&A site, as those people are more likely to know what Splunk would most usefully process.

(16 Apr '12, 10:13) Guy Harris ♦♦
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×549
×238
×2

question asked: 15 Apr '12, 18:51

question was seen: 10,018 times

last updated: 16 Apr '12, 10:13

p​o​w​e​r​e​d by O​S​Q​A