All Apps and Add-ons

NetFlow for Splunk not working after upgrading to 3.0.2

sgardne
Explorer

I have searched around the splunkbase quite a bit and have not yet found a solution. We were previously using the nfdump solution. We upgraded to the NetFlow Integrator 3.0.2 and now we don't get any data. The Integrator is configured to listen on port 9995. There is definitely traffic coming in on 9995, the UDP input for 9995 is configured, but I do not get any results when searching for "sourcetype=netflow". I've also tried removing the directory from /opt/splunk/etc/apps/ and reinstalling the app after that. Any assistance would be greatly appreciated.

0 Karma
1 Solution

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

View solution in original post

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

sgardne
Explorer

Thanks for the call yesterday. If I get some spare time, I may set up a test server with the standard edition.

0 Karma

NetFlow_Logic
Contributor

Hello sgardne, I am sorry to hear that you are having some issues and I would be happy to assist you. The app creates a default data input as follows;

UDP Port: 11514
source type: netflow

It appears you have everything configured correctly, would you be available for a secure remote session via WebEx so we can take a look? Please contact us at: support@netflowlogic.com and include your company contact info and we can schedule a session.

Thank You!

0 Karma

sgardne
Explorer

I left the default one in the inputs list and created a new UDP input and manually set its type to "netflow". I will come to your site and see about doing a remote session. Thanks.

0 Karma

sgardne
Explorer

Also it would appear the server is not even listening on port 9995.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...