All Apps and Add-ons

Can the Splunk App for Stream generate Netflow/IPFIX data?

vlado
Engager

Netflow/IPFiX data model could be used to capture the data.

Tags (2)
0 Karma
1 Solution

vshcherbakov_sp
Splunk Employee
Splunk Employee

Stream doesn't generate the exact Netflow/IPFIX data; the best approximation you can do is to create aggregated tcp and/or udp streams that have src_ip, src_port, dest_ip, dest_port (+any other fields) as key fields and bytes_in/bytes_out/packets_in/packets_out as value fields. That will generate events with NetFlow-like stats. The limitations are: only tcp and udp transport protocols supported; not all netflow fields are supported, etc. so it may or may not work based on your use case.

View solution in original post

vshcherbakov_sp
Splunk Employee
Splunk Employee

As of version 7.0, Splunk Stream supports collecting Netflow, sFlow and IPFIX data directly

vshcherbakov_sp
Splunk Employee
Splunk Employee

Stream doesn't generate the exact Netflow/IPFIX data; the best approximation you can do is to create aggregated tcp and/or udp streams that have src_ip, src_port, dest_ip, dest_port (+any other fields) as key fields and bytes_in/bytes_out/packets_in/packets_out as value fields. That will generate events with NetFlow-like stats. The limitations are: only tcp and udp transport protocols supported; not all netflow fields are supported, etc. so it may or may not work based on your use case.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...