Technology Add-on for Netflow relies on flow data processed by NetFlow Optimizer and enables you to analyse it using Splunk® Enterprise or Splunk Cloud.
It provides CIM compliant field names, eventtypes and tags for NetFlow Optimizer data.
The Add-on can also be used to generate sample events for testing purposes, it contains samples of netflow data and config files for the event generator.
Setup after installation:
[udp://10514] sourcetype = flowintegrator
[flowintegrator] homePath = $SPLUNK_DB/flowintegrator/nfi_traffic/db coldPath = $SPLUNK_DB/flowintegrator/nfi_traffic/colddb thawedPath = $SPLUNK_DB/flowintegrator/thaweddb
You also need to make sure your $SPLUNK_ROOT/etc/apps/TA-netflow/local/inputs.conf file contains the following:
[udp://10514] sourcetype = flowintegrator index = flowintegrator
Restart splunk for the configuration changes to take effect.
Further documentation can be found at:
To contact NetFlow Logic support, please visit: NetFlow Logic Support page
- Updated lookup for NetFlow Capture and Replay (available in NFO 2.6)
- Updated lookup for NFO Module for VMware NSX Distributed Firewall (available in NFO 2.6)
- Support NetFlow data reported by multiple NetFlow Optimizer instances
- Updated lookup for Palo Alto Networks, Cisco ASA modules Splunk index usage
- Improved performance
- Bug fixes
- Minor fixes
- Updates for Splunk Certification
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.