<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure nfdump to convert Netflow data from binary to text or csv? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-nfdump-to-convert-Netflow-data-from-binary-to/m-p/19582#M2780</link>
    <description>&lt;P&gt;Check out Splunk for NetFlow:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunkbase.splunk.com/apps/All/4.x/App/app:Splunk+for+NetFlow" rel="nofollow"&gt;http://splunkbase.splunk.com/apps/All/4.x/App/app:Splunk+for+NetFlow&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Feb 2011 02:11:53 GMT</pubDate>
    <dc:creator>araitz</dc:creator>
    <dc:date>2011-02-25T02:11:53Z</dc:date>
    <item>
      <title>How to configure nfdump to convert Netflow data from binary to text or csv?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-nfdump-to-convert-Netflow-data-from-binary-to/m-p/19580#M2778</link>
      <description>&lt;P&gt;I need to convert netflow data from binary to text or csv so that it can be splunked. I have downloaded nfdump and was looking for any information on how to configure it?&lt;/P&gt;

&lt;P&gt;Also, is there a better free tool then nfdump &lt;/P&gt;

&lt;P&gt;Thanks, &lt;/P&gt;

&lt;P&gt;Todd&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2010 03:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-nfdump-to-convert-Netflow-data-from-binary-to/m-p/19580#M2778</guid>
      <dc:creator>tgow</dc:creator>
      <dc:date>2010-12-31T03:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure nfdump to convert Netflow data from binary to text or csv?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-nfdump-to-convert-Netflow-data-from-binary-to/m-p/19581#M2779</link>
      <description>&lt;P&gt;Did you get it up and let it capture flows and writing it to disk?
On &lt;A href="http://nfdump.sourceforge.net/" rel="nofollow"&gt;http://nfdump.sourceforge.net/&lt;/A&gt; are the fundamentals. So after download, untar, ./configure , make , make install  ( and some dependecies like gcc, flex and others its there)&lt;/P&gt;

&lt;P&gt;to get the deamon up : nfcapd -w -D -l /flow_base_dir/router1 -p 23456   &lt;/P&gt;

&lt;P&gt;so a port per flow,,,you should then have the rolling binaries in the /flow_base_dir/router1&lt;/P&gt;

&lt;P&gt;But then comes the part which I am doubting as well, cause with nfdump you can convert the binaries to stdout in ascii and to a file as,,,,binary&lt;/P&gt;

&lt;P&gt;So it looks like you have to redirect nfdump "command for doing reversing dirs" &amp;gt;&amp;gt; file and splunk that but how to prevent dups here?&lt;/P&gt;

&lt;P&gt;OR use scripted input,,,I am hoping that someone has been so far.&lt;/P&gt;

&lt;P&gt;anyone?&lt;/P&gt;

&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2011 03:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-nfdump-to-convert-Netflow-data-from-binary-to/m-p/19581#M2779</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2011-01-13T03:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure nfdump to convert Netflow data from binary to text or csv?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-nfdump-to-convert-Netflow-data-from-binary-to/m-p/19582#M2780</link>
      <description>&lt;P&gt;Check out Splunk for NetFlow:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunkbase.splunk.com/apps/All/4.x/App/app:Splunk+for+NetFlow" rel="nofollow"&gt;http://splunkbase.splunk.com/apps/All/4.x/App/app:Splunk+for+NetFlow&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2011 02:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-nfdump-to-convert-Netflow-data-from-binary-to/m-p/19582#M2780</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-02-25T02:11:53Z</dc:date>
    </item>
  </channel>
</rss>

