All Apps and Add-ons
Highlighted

Why can't I configure multiple listeners for the Splunk Add-on for Netflow?

Communicator

Hello All,

I configured multiple listeners for NetFlow, but it seems only one listener port was available.

Listener #1
Netflow [v5], [v9] or [IPFIX] [Default: v5]: v5
Specify IP4 or IPv6 address to bind to listener [default: all]: all
UDP port to listen on: 2035
Number of seconds to rollover flow capture files for indexing [Default: 120 ]: 120

Listener #2
Netflow [v5], [v9] or [IPFIX] [Default: v5]: v5
Specify IP4 or IPv6 address to bind to listener [default: all]: all
UDP port to listen on: 2055
Number of seconds to rollover flow capture files for indexing [Default: 120 ]: 120

Listener #3
Netflow [v5], [v9] or [IPFIX] [Default: v5]: v5
Specify IP4 or IPv6 address to bind to listener [default: all]: all
UDP port to listen on: 2045
Number of seconds to rollover flow capture files for indexing [Default: 120 ]: 120

Checking the port of Listener:

netstat command

netstat -anp | grep nfcapd 
udp 0 0 0.0.0.0:2035 0.0.0.0:* 14764/nfcapd 
unix 2 [ ] DGRAM 436138807 14764/nfcapd

under bin directory

nfcapd-2-v5--2035.pid file existed

Any suggestions?

0 Karma
Highlighted

Re: Why can't I configure multiple listeners for the Splunk Add-on for Netflow?

Communicator

This is a known issue and fixed in NetFlow Add-on ver.3.0.1.

View solution in original post

0 Karma