Getting Data In

How can I get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise

abdulhasnath
New Member

Hi,

Can someone direct me on what app I need to install to get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise?

I have installed a forwarder and set the deployment/receiver server address to the address of where Splunk Enterprise is installed.
I have followed the Splunk Stream guide, and installed this app. Is this the right way?

Many thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

In addition to pointing the forwarder at Splunk Enterprise, you must also tell Splunk Enterprise to accept data from the forwarder.
Go to Settings->Forwarding and receiving and click "Add new" under Receiving. Enter the port number to listen on (usually 9997) and click Save.

---
If this reply helps you, Karma would be appreciated.
0 Karma

abdulhasnath
New Member

Thanks for your answer. I have installed the forwarder + Splunk Enterprise on a server we have. How do I configure it to receive information from my NetFlow appliance, or is it just the case of me sending this information to the IP address + port number of the server that forwarder sits on from my appliance? If so, how do I then view this information on Splunk Enterprise? Sorry for all the questions, this is something new to us.

0 Karma

abdulhasnath
New Member

Also is it possible to add a 'pcap' file and view it in Splunk through dashboards? I've uploaded it via Settings>Data input but cannot see anything, I have also installed Splunk for PCAP files but no success?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...