<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Stream in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Stream/m-p/505386#M86115</link>
    <description>&lt;P&gt;Dear&lt;/P&gt;&lt;P&gt;I am using network monitoring sensor (linux machine). I have deployed universal forwarder on this sensor. What i am looking for is to ingest IPFIX data directly from incoming interface on this sensor (eth0) or from a directory (file) and send this data to the Indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking to a Splink Stream documentation I cant find proper way to solve this problem.&lt;/P&gt;&lt;P&gt;Looking forward to reading from you soon&lt;/P&gt;</description>
    <pubDate>Sun, 21 Jun 2020 16:43:13 GMT</pubDate>
    <dc:creator>mdespot</dc:creator>
    <dc:date>2020-06-21T16:43:13Z</dc:date>
    <item>
      <title>Splunk Stream</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Stream/m-p/505386#M86115</link>
      <description>&lt;P&gt;Dear&lt;/P&gt;&lt;P&gt;I am using network monitoring sensor (linux machine). I have deployed universal forwarder on this sensor. What i am looking for is to ingest IPFIX data directly from incoming interface on this sensor (eth0) or from a directory (file) and send this data to the Indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking to a Splink Stream documentation I cant find proper way to solve this problem.&lt;/P&gt;&lt;P&gt;Looking forward to reading from you soon&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jun 2020 16:43:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Stream/m-p/505386#M86115</guid>
      <dc:creator>mdespot</dc:creator>
      <dc:date>2020-06-21T16:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Stream</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Stream/m-p/505408#M86116</link>
      <description>&lt;P class="lia-align-left"&gt;Have you gone through the Splunk Stream Supported protocols?&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/ProtocolDetection" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/ProtocolDetection&lt;/A&gt;&amp;nbsp;You'll notice, that IPFIX is not listed here.&lt;/P&gt;&lt;P class="lia-align-left"&gt;Now that being said, you can use Netflow to aggregate IPFIX flows into stream. This is documented here :&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoingestNetflowandIPFIXdata" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoingestNetflowandIPFIXdata&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Another option is that you can also ingest pcap files that have IPFIX in them also :&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoparsePCAPfiles" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/UseStreamtoparsePCAPfiles&lt;/A&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Most of your stream questions regarding configuration, deployment, and protocol support can be found here :&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/AboutSplunkAppforStream" target="_blank"&gt;https://docs.splunk.com/Documentation/StreamApp/7.2.0/DeployStreamApp/AboutSplunkAppforStream&lt;/A&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 01:26:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Stream/m-p/505408#M86116</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2020-06-22T01:26:49Z</dc:date>
    </item>
  </channel>
</rss>

