<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NSX-T IPFIX and Splunk in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577457#M10892</link>
    <description>&lt;P&gt;Thanks for your reply,&lt;BR /&gt;I upgrade to 8.2.2.1 and install Splunk Stream and config and edit streamfwdlog. conf file in splunk_app_stream/local directory and then restart Splunk but still did not receive any IPFIX&lt;/P&gt;&lt;P&gt;[streamfwd]&lt;BR /&gt;logConfig = streamfwdlog.conf&lt;BR /&gt;port = 4739&lt;/P&gt;&lt;P&gt;netflowReceiver.0.ip = [ip address]&lt;BR /&gt;netflowReceiver.0.port = 4739&lt;BR /&gt;netflowReceiver.0.protocol = udp&lt;BR /&gt;netflowReceiver.0.decoder = netflow&lt;/P&gt;</description>
    <pubDate>Mon, 06 Dec 2021 11:39:21 GMT</pubDate>
    <dc:creator>Hamidreza74</dc:creator>
    <dc:date>2021-12-06T11:39:21Z</dc:date>
    <item>
      <title>NSX-T IPFIX and Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577364#M10889</link>
      <description>&lt;P&gt;We are using Splunk 7.2.6&amp;nbsp; as our Syslog server in our network environment.&lt;/P&gt;&lt;P&gt;On the Splunk server, I added the IPFIX add-on, and on the NSX-T point the IPFIX target to the SplunkSrv:&lt;SPAN&gt;4739.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We use the exact same configuration on our previous NSX-V and we were able to receive all the related packets on Splunk, but in NSX-T we are unable to do so.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We check everything, local firewall rules on Splunk included, but still no chance. also, I check the Splunk server with Wireshark and I got IPFIX traffic but it doesn't show in Splunk&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any thoughts?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 16:40:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577364#M10889</guid>
      <dc:creator>Hamidreza74</dc:creator>
      <dc:date>2021-12-05T16:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-T IPFIX and Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577367#M10890</link>
      <description>&lt;P&gt;OK, so you must be using something else apart from "bare" Splunk Enterprise since Splunk on its own cannot ingest IPFIX. And IPFIX receiving has definitely nothing to do with syslog.&lt;/P&gt;&lt;P&gt;So question is - what are you using for IPFIX ingestion? Splunk Stream?&lt;/P&gt;&lt;P&gt;Check this solution's configuration.&lt;/P&gt;&lt;P&gt;And BTW, 7.2.6 is already end-of-life so you should have already upgraded to a current version.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Dec 2021 18:29:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577367#M10890</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-05T18:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-T IPFIX and Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577457#M10892</link>
      <description>&lt;P&gt;Thanks for your reply,&lt;BR /&gt;I upgrade to 8.2.2.1 and install Splunk Stream and config and edit streamfwdlog. conf file in splunk_app_stream/local directory and then restart Splunk but still did not receive any IPFIX&lt;/P&gt;&lt;P&gt;[streamfwd]&lt;BR /&gt;logConfig = streamfwdlog.conf&lt;BR /&gt;port = 4739&lt;/P&gt;&lt;P&gt;netflowReceiver.0.ip = [ip address]&lt;BR /&gt;netflowReceiver.0.port = 4739&lt;BR /&gt;netflowReceiver.0.protocol = udp&lt;BR /&gt;netflowReceiver.0.decoder = netflow&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 11:39:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577457#M10892</guid>
      <dc:creator>Hamidreza74</dc:creator>
      <dc:date>2021-12-06T11:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-T IPFIX and Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577462#M10893</link>
      <description>&lt;P&gt;I don't know splunk stream that much but firstly I'd simply check whether&lt;/P&gt;&lt;P&gt;a) There is an open port on splunk side. For example with&lt;/P&gt;&lt;PRE&gt;netstat -unpl | grep :4739&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;b) There are no firewall rules in place filtering out the traffic.&lt;/P&gt;&lt;P&gt;c) In case of UDP you could also hit a problem with rare cases with rp_filter (binding to particular IP could suggest some multi-homed configuration which could be prone to such effects).&lt;/P&gt;</description>
      <pubDate>Mon, 06 Dec 2021 11:54:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577462#M10893</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-12-06T11:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-T IPFIX and Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577602#M10899</link>
      <description>&lt;P&gt;There is no open Port for 4739 in the Splunk side&lt;BR /&gt;I check the firewall seting, there is no Firewall rule.&amp;nbsp;&lt;BR /&gt;is there anything I missed in the configuration file?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;logConfig = streamfwdlog.conf&lt;BR /&gt;port = 8889&lt;/P&gt;&lt;P&gt;netflowReceiver.0.ip = 0.0.0.0&lt;BR /&gt;netflowReceiver.0.port = 4739&lt;BR /&gt;netflowReceiver.0.protocol = udp&lt;BR /&gt;netflowReceiver.0.decoder = netflow&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 11:29:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577602#M10899</guid>
      <dc:creator>Hamidreza74</dc:creator>
      <dc:date>2021-12-07T11:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: NSX-T IPFIX and Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577610#M10901</link>
      <description>&lt;P&gt;I got IPFIX traffic and I can see with Wireshark but I can't see any log in Splunk, I try to change the port but is not work yet&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 12:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/NSX-T-IPFIX-and-Splunk/m-p/577610#M10901</guid>
      <dc:creator>Hamidreza74</dc:creator>
      <dc:date>2021-12-07T12:38:22Z</dc:date>
    </item>
  </channel>
</rss>

