Hi Guys,
I have installed the Splunk Add-on for NetFlow and also checked transforms.conf, fields but I can't see about src_inf or dst_inf values e.g: interface name Ethernet 0/0... How do I capture interface name? Thank you so much.
if it's in the flow data, you can just use Splunk's field extractor to do what you want. http://docs.splunk.com/Documentation/Splunk/6.3.1/Knowledge/ExtractfieldsinteractivelywithIFX
Hello, I have two questions about your post:
1) What are these flows coming from (Cisco router, VMware NSX, nProbe)?
2) Is NetFlow or IPFIX being exported?
note: i collect cisco router and switch devices
Please paste in your flexible netflow configuration.