All Apps and Add-ons

How to create network monitoring report for netflow and sflow data ?

akg2019
Explorer

Hi,

I have ingested netflow and sflow wire data into splunk from our Juniper switches. But there is no visualization app with inbuilt/default dashboards. Basically i am looking for network monitoring report via Splunk similar to Manage Engine/Solarwinds/Ipswitch dashboards.

In the report i wanted to calculate metrics such as bitrate (bps) and traffic volume (bytes transferred in MB/GB).
The search query should calculate these metrics for both netflow and sflow data which has the relevant data in different field names.

Sample ingested sflow V5 and netflow V9 data fields are attached.

alt text

alt text

Thanks,
AKG

0 Karma

DavidHourani
Super Champion

Hi @akg2019,

We can continue the discussion from this link https://answers.splunk.com/answers/663850/using-splunk-stream-for-netflow-now-ingesting-but.html#com... here.

Cheers,
David

0 Karma

akg2019
Explorer

Hi David,

For sflow: I could not find any Splunk documentation reference. Any thoughts on the below queries related to sflow ?

What are the fields that has to be used for calculating bitrate in sflow?
What is the formula for calculating bitrate from sflow V5 data ?

For Netflow:
What is the formula for calculating bitrate from Netflow V9 data ?

0 Karma

DavidHourani
Super Champion

I see so many questions about this with no answer haha : https://answers.splunk.com/answers/740793/monitor-bandwidth-with-netflow.html

So lets try to get an answer, have a look at this, it seems like a good explanation for in out :
https://blogs.manageengine.com/network/netflowanalyzer/2009/02/24/in-and-out-reports-with-netflow-an...

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...