All Apps and Add-ons

Why can't I configure multiple listeners for the Splunk Add-on for Netflow?

CurryPan
Communicator

Hello All,

I configured multiple listeners for NetFlow, but it seems only one listener port was available.

Listener #1
Netflow [v5], [v9] or [IPFIX] [Default: v5]: v5
Specify IP4 or IPv6 address to bind to listener [default: all]: all
UDP port to listen on: 2035
Number of seconds to rollover flow capture files for indexing [Default: 120 ]: 120

Listener #2
Netflow [v5], [v9] or [IPFIX] [Default: v5]: v5
Specify IP4 or IPv6 address to bind to listener [default: all]: all
UDP port to listen on: 2055
Number of seconds to rollover flow capture files for indexing [Default: 120 ]: 120

Listener #3
Netflow [v5], [v9] or [IPFIX] [Default: v5]: v5
Specify IP4 or IPv6 address to bind to listener [default: all]: all
UDP port to listen on: 2045
Number of seconds to rollover flow capture files for indexing [Default: 120 ]: 120

Checking the port of Listener:

netstat command

netstat -anp | grep nfcapd 
udp 0 0 0.0.0.0:2035 0.0.0.0:* 14764/nfcapd 
unix 2 [ ] DGRAM 436138807 14764/nfcapd

under bin directory

nfcapd-2-v5--2035.pid file existed

Any suggestions?

0 Karma
1 Solution

CurryPan
Communicator

This is a known issue and fixed in NetFlow Add-on ver.3.0.1.

View solution in original post

0 Karma

CurryPan
Communicator

This is a known issue and fixed in NetFlow Add-on ver.3.0.1.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...