<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can cflowd format be Splunked? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125126#M25810</link>
    <description>&lt;P&gt;After some googling I learned that &lt;CODE&gt;cflowd is a flow analysis tool that was used for analyzing Cisco's NetFlow enabled switching method&lt;/CODE&gt; So, if it uses &lt;CODE&gt;netflow&lt;/CODE&gt; you can check out any of the netflow apps &lt;A href="https://apps.splunk.com/apps/#/search/netflow/page/1"&gt;https://apps.splunk.com/apps/#/search/netflow/page/1&lt;/A&gt; maybe they can be of help in this case&lt;/P&gt;</description>
    <pubDate>Tue, 10 Feb 2015 11:15:03 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2015-02-10T11:15:03Z</dc:date>
    <item>
      <title>Can cflowd format be Splunked?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125123#M25807</link>
      <description>&lt;P&gt;Hello. &lt;BR /&gt;
A customer is getting external firewall logs from a vendor in "cflowd format".&lt;BR /&gt;
Can cflowd format be Splunked? If so, any documentation or info re the same would be awesome.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 07:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125123#M25807</guid>
      <dc:creator>juthsn</dc:creator>
      <dc:date>2015-02-03T07:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can cflowd format be Splunked?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125124#M25808</link>
      <description>&lt;P&gt;Hi juthsn,&lt;/P&gt;

&lt;P&gt;the answer is as easy as this:&lt;/P&gt;

&lt;P&gt;If this format is human readable: yes, Splunk can index it.&lt;BR /&gt;
If this format is binary/non-readable by humans: no, Splunk cannot index it.&lt;/P&gt;

&lt;P&gt;For the later, you could still use some external conversion script and have the output of this script index by Splunk.&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2015 07:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125124#M25808</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-03T07:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can cflowd format be Splunked?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125125#M25809</link>
      <description>&lt;P&gt;Hi, let me rephrase then &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
Has anybody worked with this format before? We have never seen the raw data in this type of file and are not sure if it is human readable ascii. &lt;BR /&gt;
Wasn't able to find a sample file either.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 10:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125125#M25809</guid>
      <dc:creator>juthsn</dc:creator>
      <dc:date>2015-02-10T10:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can cflowd format be Splunked?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125126#M25810</link>
      <description>&lt;P&gt;After some googling I learned that &lt;CODE&gt;cflowd is a flow analysis tool that was used for analyzing Cisco's NetFlow enabled switching method&lt;/CODE&gt; So, if it uses &lt;CODE&gt;netflow&lt;/CODE&gt; you can check out any of the netflow apps &lt;A href="https://apps.splunk.com/apps/#/search/netflow/page/1"&gt;https://apps.splunk.com/apps/#/search/netflow/page/1&lt;/A&gt; maybe they can be of help in this case&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 11:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-cflowd-format-be-Splunked/m-p/125126#M25810</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-10T11:15:03Z</dc:date>
    </item>
  </channel>
</rss>

