Monitoring Splunk

How can I monitor T1 all activity to determine periodic slowdown?

nola50
New Member

I have an account that I am headed to 11/09/2011 that the Internet is slowing down at different times of the day. I'd like to monitor the traffic of the site and see what could be the issue. There is no server installed, just about 10 users doing data entry and accessing the Internet.

How can I setup Splunk to monitor and see what's causing the slow down?

Tags (2)
0 Karma

nola50
New Member

It's a Cisco 1721 and looks like it supports Netflow. I'll have to see what it takes to get the app to load and run.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Obviously, you would need some kind of data source that describes the flow of traffic through the Internet connection. For most folks, this would mean getting data out of the edge router.

One data source is SNMP counters. You can script up snmpget to log data about ifInOctets and ifOutOctets on the router, and then Splunk that. This will tell you if there is a bandwidth issue, but not necessarily what is causing it.

Another data source is Netflow. There is an app for that which enables Splunk to load/process Netflow data. However, not all routers have the ability to export Netflow data.

Your mileage may vary in using either of these to resolve your client's issue. This isn't an incredibly straightforward problem to resolve either with Splunk or without.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...