<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk network monitoring in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402048#M71528</link>
    <description>&lt;P&gt;Splunk is a data tool, for it to help you with those issues, you would need to provide the information required to identify the issue.&lt;/P&gt;

&lt;P&gt;specifically I need to catch network errors for things like, &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;dropped packets or connections&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;You will need to define what you mean here, packets are dropped on networks all the time. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;any kind of network error&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;blockage by firewall or switch ACL&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;any other form of connection data&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Fri, 18 May 2018 13:12:04 GMT</pubDate>
    <dc:creator>solarboyz1</dc:creator>
    <dc:date>2018-05-18T13:12:04Z</dc:date>
    <item>
      <title>Splunk network monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402047#M71527</link>
      <description>&lt;P&gt;Hello, I am trying to figure out hwo we can use Splunk to monitor and report on our network, &lt;/P&gt;

&lt;P&gt;specifically I need to catch network errors for things like, &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;dropped packets or connections&lt;/LI&gt;
&lt;LI&gt;any kind of network error&lt;/LI&gt;
&lt;LI&gt;blockage by firewall or switch ACL&lt;/LI&gt;
&lt;LI&gt;any other form of connection data&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I tried Splunk Stream, which gives us a lot of data of general chatter and bandwidth info, but its not very useful for detecting network errors or troubleshooting problems&lt;/P&gt;

&lt;P&gt;Is there an app or examples on how to set something like this up? Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 15:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402047#M71527</guid>
      <dc:creator>perfecto25</dc:creator>
      <dc:date>2018-05-17T15:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk network monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402048#M71528</link>
      <description>&lt;P&gt;Splunk is a data tool, for it to help you with those issues, you would need to provide the information required to identify the issue.&lt;/P&gt;

&lt;P&gt;specifically I need to catch network errors for things like, &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;dropped packets or connections&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;You will need to define what you mean here, packets are dropped on networks all the time. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;any kind of network error&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;blockage by firewall or switch ACL&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;any other form of connection data&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 18 May 2018 13:12:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402048#M71528</guid>
      <dc:creator>solarboyz1</dc:creator>
      <dc:date>2018-05-18T13:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk network monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402049#M71529</link>
      <description>&lt;P&gt;What I meant to say:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;dropped packets or connections&lt;/LI&gt;
&lt;LI&gt;any kind of network error&lt;/LI&gt;
&lt;LI&gt;blockage by firewall or switch ACL&lt;/LI&gt;
&lt;LI&gt;any other form of connection data&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Configure switches/routers/firewall to syslog to your splunk instance. &lt;BR /&gt;
Install the appropriate apps for the network devices used. &lt;/P&gt;

&lt;P&gt;You can install streams and capture the metadata, or configure netflow collectors and send to streams.&lt;BR /&gt;
All depends on what you have available and what you are trying to do.&lt;/P&gt;

&lt;P&gt;But getting the logs from you network devices is probably a good first step and will meet many if not all of your needs. &lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 13:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402049#M71529</guid>
      <dc:creator>solarboyz1</dc:creator>
      <dc:date>2018-05-18T13:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk network monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402050#M71530</link>
      <description>&lt;P&gt;You may need to collect the following data in Splunk:&lt;/P&gt;

&lt;P&gt;*&amp;gt;dropped packets or connections&lt;BR /&gt;
*&amp;gt;any kind of network error&lt;/P&gt;

&lt;P&gt;You can get this information from SNMP polling/traps or sFlow counters or certain NetFlow/IPFIX records&lt;/P&gt;

&lt;P&gt;*&amp;gt;blockage by firewall or switch ACL&lt;BR /&gt;
syslogs or NetFlow data&lt;/P&gt;

&lt;P&gt;*&amp;gt;any other form of connection data&lt;BR /&gt;
NetFlow, sFlow, IPFIX&lt;/P&gt;

&lt;P&gt;We are a Splunk partner and we provide all this data (except syslog, which is natively ingested by Splunk) with our product - NetFlow Optimizer.&lt;/P&gt;

&lt;P&gt;Try it for free by visiting &lt;A href="https://www.netflowlogic.com/download/"&gt;https://www.netflowlogic.com/download/&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 00:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-network-monitoring/m-p/402050#M71530</guid>
      <dc:creator>NetFlow_Logic</dc:creator>
      <dc:date>2018-06-13T00:44:20Z</dc:date>
    </item>
  </channel>
</rss>

