<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I index Netflow? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16460#M1992</link>
    <description>&lt;P&gt;"Splunk for NetFlow" App is replaced with "NetFlow for Splunk". See this link: &lt;A href="http://splunk-base.splunk.com/apps/22328/netflow-for-splunk-powered-by-netflow-integrator"&gt;http://splunk-base.splunk.com/apps/22328/netflow-for-splunk-powered-by-netflow-integrator&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jan 2013 23:31:28 GMT</pubDate>
    <dc:creator>NetFlow_Logic</dc:creator>
    <dc:date>2013-01-21T23:31:28Z</dc:date>
    <item>
      <title>How can I index Netflow?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16456#M1988</link>
      <description>&lt;P&gt;I want to be able to search netflow data to find suspicious conversations (i.e. someone opening a connection and closing it right away). Is there a way to get a netflow feed into Splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2010 22:35:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16456#M1988</guid>
      <dc:creator>Dan</dc:creator>
      <dc:date>2010-06-29T22:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: How can I index Netflow?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16457#M1989</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/wiki/Apps:TrafficFlows" rel="nofollow"&gt;http://www.splunk.com/wiki/Apps:TrafficFlows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2010 00:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16457#M1989</guid>
      <dc:creator>rayfoo</dc:creator>
      <dc:date>2010-06-30T00:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can I index Netflow?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16458#M1990</link>
      <description>&lt;P&gt;Netflow data is binary and, even though you could splunk it like that, it would not be useful in that form inside your Splunk GUI while searching. Therefore, the flow will need to be converted to humanly-readable text first via some NetFlow-2-Text converter, such as the ones mentioned at the "TrafficFlows" link provided in the previous answer.&lt;/P&gt;

&lt;P&gt;Once converted to text, however, you could then easily setup Splunk to listen on any open tcp or udp port for incoming converted flow streams and just send the it directly to that port and SPlunk will index it in real time.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2010 20:59:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16458#M1990</guid>
      <dc:creator>maverick</dc:creator>
      <dc:date>2010-08-18T20:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: How can I index Netflow?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16459#M1991</link>
      <description>&lt;P&gt;See this link for the Splunk for Netflow App:   &lt;A href="http://splunkbase.splunk.com/apps/All/4.x/app:Splunk+for+NetFlow"&gt;http://splunkbase.splunk.com/apps/All/4.x/app:Splunk+for+NetFlow&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2011 09:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16459#M1991</guid>
      <dc:creator>maverick</dc:creator>
      <dc:date>2011-03-18T09:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: How can I index Netflow?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16460#M1992</link>
      <description>&lt;P&gt;"Splunk for NetFlow" App is replaced with "NetFlow for Splunk". See this link: &lt;A href="http://splunk-base.splunk.com/apps/22328/netflow-for-splunk-powered-by-netflow-integrator"&gt;http://splunk-base.splunk.com/apps/22328/netflow-for-splunk-powered-by-netflow-integrator&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2013 23:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16460#M1992</guid>
      <dc:creator>NetFlow_Logic</dc:creator>
      <dc:date>2013-01-21T23:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: How can I index Netflow?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16461#M1993</link>
      <description>&lt;P&gt;All previously existing versions of NetFlow Logic Splunk apps have been merged into one NetFlow for Splunk by NetFlow Logic App. See this link &lt;A href="http://apps.splunk.com/app/489/"&gt;http://apps.splunk.com/app/489/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 18:31:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-index-Netflow/m-p/16461#M1993</guid>
      <dc:creator>NetFlow_Logic</dc:creator>
      <dc:date>2014-03-10T18:31:25Z</dc:date>
    </item>
  </channel>
</rss>

