<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Splunk Stream for Netflow- now, ingesting but how to graph? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443317#M54544</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33185"&gt;@keiran_harris&lt;/a&gt; and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/169937"&gt;@akg2019&lt;/a&gt;  can i know how you integrated netflow logs into splunk using stream app, i was going through documentation but its still confusing to me, much appreciate your response on this, Thanks ,@akg2019 and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33185"&gt;@keiran_harris&lt;/a&gt; how did you ingested netflow logs using stream app, i would like to know the process, i went through the splunk documentation but its still little confusing to me, appreciate your response on this&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:15:41 GMT</pubDate>
    <dc:creator>nikhilafedex</dc:creator>
    <dc:date>2020-09-30T02:15:41Z</dc:date>
    <item>
      <title>Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443278#M54505</link>
      <description>&lt;P&gt;Hi splunk gurus! &lt;/P&gt;

&lt;P&gt;Long weekend here in Australia and i thought id finally get around to ticking something off my wish list: netflow my home network. &lt;/P&gt;

&lt;P&gt;So ive got a cisco adsl router thats successfully streaming netflow to my splunk box (verified first with tcpdump). At the splunk side, i started off down one path (“Netflow Analytics” until i realised you had to pay, a lot, for that!)... then some searching in here pointed me to “splunk stream”, which seems robust, is free, now installed, and happily gobbling up my netflow stream!  See attached photo. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5148iFCC4C293FFA9E556/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Which brings me to the fun part (and my question). Where can i find some pre-canned SPL to start plotting my traffic on pretty graphs? The Stream UI doesnt look to be setup for this. I know i could start to write myself but its a relatively complex dataset, and surely this has been done lots before, so i shouldnt have to reinvent the wheel. So if anyone can point me at some SPL  (or an app!) that would be great! &lt;/P&gt;

&lt;P&gt;Thanks in advance all. &lt;BR /&gt;
Keiran. &lt;/P&gt;

&lt;P&gt;PS- this is the sort of graph I'm hoping to create (from the paid app - &lt;A href="https://splunkbase.splunk.com/app/489):"&gt;https://splunkbase.splunk.com/app/489):&lt;/A&gt; &lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5149iC2098B5C47BB8ACA/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jun 2018 22:51:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443278#M54505</guid>
      <dc:creator>keiran_harris</dc:creator>
      <dc:date>2018-06-10T22:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443279#M54506</link>
      <description>&lt;P&gt;Giving this a nudge so it bubbles up again for some viewers who can help!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 12:38:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443279#M54506</guid>
      <dc:creator>keiran_harris</dc:creator>
      <dc:date>2018-06-15T12:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443280#M54507</link>
      <description>&lt;P&gt;Agree, top up, I need it too.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 05:18:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443280#M54507</guid>
      <dc:creator>xiongwei002</dc:creator>
      <dc:date>2018-08-23T05:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443281#M54508</link>
      <description>&lt;P&gt;Looking for some light into this too, I'm under the same boat, I loved the Netflow pay app and it works but will like to have the same type of dashboard with the Stream app.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2019 12:27:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443281#M54508</guid>
      <dc:creator>Zolrak</dc:creator>
      <dc:date>2019-01-12T12:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443282#M54509</link>
      <description>&lt;P&gt;Hi Together, &lt;/P&gt;

&lt;P&gt;same situation for me!&lt;BR /&gt;
i ingested netflow from our cisco-routers to splunk via Splunk app for stream.&lt;BR /&gt;
Now i want to visualize it. &lt;/P&gt;

&lt;P&gt;@keiran_harris do you have some results jet? &lt;/P&gt;

&lt;P&gt;Regards, Tobias,Hi together, &lt;/P&gt;

&lt;P&gt;same situation for me!&lt;BR /&gt;
We also ingested netflow from our cisco-router and want to visualize it now.&lt;BR /&gt;
@keiran_harris do you have some results jet? &lt;/P&gt;

&lt;P&gt;Regards, Tobias&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 06:34:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443282#M54509</guid>
      <dc:creator>tobiasgoevert</dc:creator>
      <dc:date>2019-02-22T06:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443283#M54510</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have ingested netflow and sflow wire data from our Juniper switches. But there is no visualization app with inbuilt/default dashboards. Can someone help with SPL queries or apps that can visualize the data similar to Manage Engine/Solarwinds dashboards?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
AKG&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 06:24:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443283#M54510</guid>
      <dc:creator>akg2019</dc:creator>
      <dc:date>2019-05-20T06:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443284#M54511</link>
      <description>&lt;P&gt;sure, what are you trying to build ? &lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 06:31:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443284#M54511</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-20T06:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443285#M54512</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;

&lt;P&gt;I am trying to create custom dashboard report that lists the top N source to destination conversation by bit rate (bps) and traffic volume (Total MB/GB).&lt;/P&gt;

&lt;P&gt;Post this i wanted to include other fields like port and Interface ID's as well.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
AKG&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 06:47:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443285#M54512</guid>
      <dc:creator>akg2019</dc:creator>
      <dc:date>2019-05-20T06:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443286#M54513</link>
      <description>&lt;P&gt;@akg2019, you're looking for something like this : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=whereYourDataIs sourcetype=yourSourcetype | stats avg(bps) as bitRate, sum(bps) as volume by src dest
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 May 2019 06:53:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443286#M54513</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-20T06:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443287#M54514</link>
      <description>&lt;P&gt;Hi David,&lt;BR /&gt;
Thanks for the search query. However bps is not captured directly. For example in sflow data there is no field such as bps. It has to be calculated manually. Same applies to netflow as well.&lt;/P&gt;

&lt;P&gt;I am looking for the search queries that calculates bitrate (bps) and traffic volume (bytes transferred in MB/GB). The search query should calculate these metrics for both netflow and sflow data which has the relevant data in different field names.&lt;/P&gt;

&lt;P&gt;Basically i am looking for network monitoring report via Splunk. Any help on this is highly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 07:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443287#M54514</guid>
      <dc:creator>akg2019</dc:creator>
      <dc:date>2019-05-20T07:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443288#M54515</link>
      <description>&lt;P&gt;Can you make it into a new question please and include a sample event line ? We can work from there &lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 07:10:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443288#M54515</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-20T07:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443289#M54516</link>
      <description>&lt;P&gt;Sure David&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 07:45:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443289#M54516</guid>
      <dc:creator>akg2019</dc:creator>
      <dc:date>2019-05-20T07:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443290#M54517</link>
      <description>&lt;P&gt;Hi all, i havent had time to look at this further. My splunk is still ingesting loads of netflow, but i havent started dev on the SPL. Seems lots of people looking for this. @DavidHourani  has specifically asked for a new question to be asked on a new post, not quite sure why, its still the same dev problem we need solved, but regardless happy to follow the new thread, just pls link us in here @akg2019  so we know where to follow. Thanks guys! &lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 08:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443290#M54517</guid>
      <dc:creator>keiran_harris</dc:creator>
      <dc:date>2019-05-20T08:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443291#M54518</link>
      <description>&lt;P&gt;Hi David and Keiran,&lt;/P&gt;

&lt;P&gt;I have created a new post. Please follow the below link.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/747044/how-to-create-network-monitoring-report-for-netflo.html?minQuestionBodyLength=80"&gt;https://answers.splunk.com/answers/747044/how-to-create-network-monitoring-report-for-netflo.html?minQuestionBodyLength=80&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Subject : How to create network monitoring report for netflow and sflow data ?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
AKG&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 08:11:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443291#M54518</guid>
      <dc:creator>akg2019</dc:creator>
      <dc:date>2019-05-20T08:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443292#M54519</link>
      <description>&lt;P&gt;link is not working for me XD&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 08:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443292#M54519</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-20T08:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443293#M54520</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;

&lt;P&gt;The new post status is "This post is currently awaiting moderation. If you believe this to be in error, contact a system administrator."&lt;/P&gt;

&lt;P&gt;Not sure when it will get approved.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 08:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443293#M54520</guid>
      <dc:creator>akg2019</dc:creator>
      <dc:date>2019-05-20T08:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443294#M54521</link>
      <description>&lt;P&gt;ouch... okay, let me know when it's up, and if you want go ahead and share some sample (anonymized) logs here so we can work with it.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2019 08:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443294#M54521</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-20T08:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443295#M54522</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/68181"&gt;@DavidHourani&lt;/a&gt;  - &lt;STRONG&gt;really&lt;/STRONG&gt; appreciate your assistance here.... attached is a screenshot of some sample data thats as good as any other. Let me know if you need an actual export. &lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://ibb.co/35XJC0x" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Basically (if you didnt know about netflow) the router sends periodical "flow records" back to a reciever - in this case splunk  (FYI - each data packet can contain many flow records, and splunk pulls them out as an event per record).... so its a snapshot into what the routers session table is at that moment, inclusive of byte count for those transiting sessions. So if you have a long running TCP session to a DB server for instance, at minute one, it will have a byte count (bytes_in/out) of say 100.... check back 1 minute later, it migth have a byte count of say 1000, indicating 900 more bytes in that last minute. &lt;/P&gt;

&lt;P&gt;I think the search logic needs to &lt;BR /&gt;
- group like flows by TCP/UDP sessions which is (src_ip + dst_ip + src_port + dest_port)..... &lt;BR /&gt;
- graphing bytes over time. &lt;BR /&gt;
- And then grabbing only say the top 10 flows by byte count. &lt;BR /&gt;
Check the original post for the kind of flow data visualisation over time we are hoping for. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:38:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443295#M54522</guid>
      <dc:creator>keiran_harris</dc:creator>
      <dc:date>2020-09-30T00:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443296#M54523</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;

&lt;P&gt;The new post is yet to be approved. Lets continue working in this thread.&lt;/P&gt;

&lt;P&gt;Basically i am looking for network monitoring report via Splunk similar to Manage Engine/Solarwinds/Ipswitch dashboards.&lt;/P&gt;

&lt;P&gt;In the report i wanted to calculate metrics such as bitrate (bps) and traffic volume (bytes transferred in MB/GB). &lt;BR /&gt;
The search query should calculate these metrics for both netflow and sflow data which has the relevant data in different field names.&lt;/P&gt;

&lt;P&gt;Sample ingested sflow V5 and netflow V9 data fields are attached.&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/273718-sflow-v5-event-20may2019.jpg" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/273719-netflow-v9-event-20may2019.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;Can you please help in creating a standard network monitoring report that contains source_IP , dest_IP , Port , Bitrate  (bps) , Bytes (MB/GB) etc..   for a given time range.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
AKG&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:36:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443296#M54523</guid>
      <dc:creator>akg2019</dc:creator>
      <dc:date>2020-09-30T00:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Stream for Netflow- now, ingesting but how to graph?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443297#M54524</link>
      <description>&lt;P&gt;so if my understanding is correct, you have the source and dest port in sflow, the bytes_in in netflow and you wish to combine both of them ?&lt;/P&gt;

&lt;P&gt;In that case running a search like this should do the trick : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=yourIndex sourcetype=yoursourcetype | stats values(bytes_in) as bytes_in, values(dest_port) as dest_port values(src_port) as src_port by src_ip, dest_ip | eventstats sum(bytes_in) as volume, avg(bytes_in) as Bps by src_ip, dest_ip
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 20 May 2019 11:08:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Using-Splunk-Stream-for-Netflow-now-ingesting-but-how-to-graph/m-p/443297#M54524</guid>
      <dc:creator>DavidHourani</dc:creator>
      <dc:date>2019-05-20T11:08:47Z</dc:date>
    </item>
  </channel>
</rss>

