<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to ingest netflow/sflow logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-netflow-sflow-logs/m-p/291917#M55644</link>
    <description>&lt;P&gt;We intend to collected netflow/sflow logs in our Splunk Enterprise solution. I read that there is an app required to collect logs. Also I came across splunk docs to configure flow collector- &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.1.0/DeployStreamApp/ConfigureFlowcollector"&gt;https://docs.splunk.com/Documentation/StreamApp/7.1.0/DeployStreamApp/ConfigureFlowcollector&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This link doesn't mention about app.  Do I need the app or the process mention in docs? which is recommended method?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jun 2017 20:02:16 GMT</pubDate>
    <dc:creator>hkumar26</dc:creator>
    <dc:date>2017-06-29T20:02:16Z</dc:date>
    <item>
      <title>How to ingest netflow/sflow logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-netflow-sflow-logs/m-p/291917#M55644</link>
      <description>&lt;P&gt;We intend to collected netflow/sflow logs in our Splunk Enterprise solution. I read that there is an app required to collect logs. Also I came across splunk docs to configure flow collector- &lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.1.0/DeployStreamApp/ConfigureFlowcollector"&gt;https://docs.splunk.com/Documentation/StreamApp/7.1.0/DeployStreamApp/ConfigureFlowcollector&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This link doesn't mention about app.  Do I need the app or the process mention in docs? which is recommended method?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 20:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-netflow-sflow-logs/m-p/291917#M55644</guid>
      <dc:creator>hkumar26</dc:creator>
      <dc:date>2017-06-29T20:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to ingest netflow/sflow logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-netflow-sflow-logs/m-p/291918#M55645</link>
      <description>&lt;P&gt;there are several possibilities for it with pro/con each time&lt;BR /&gt;
if you go the stream way, just install the stream app following the docs and configure it to collect your network data directly. (ie your network device will send them to stream)&lt;BR /&gt;
for the collection part, it can be a UF with stream TA (probably easier to start with) or a streamfwd &lt;/P&gt;

&lt;P&gt;if you go the TA way without stream, the splunk TA for netflow include a collector for netflow , which will make the conversion to log files before data being injected into splunk   (so the future is probably to go the stream way)&lt;/P&gt;

&lt;P&gt;or there's another third party TA including a collector on splunkbase, altough you'll probably need a specific license for it.&lt;/P&gt;

&lt;P&gt;so look to all solutions, tests and choose the one that best fit your needs&lt;/P&gt;

&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2017 21:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-ingest-netflow-sflow-logs/m-p/291918#M55645</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2017-06-29T21:56:17Z</dc:date>
    </item>
  </channel>
</rss>

