Getting Data In

How can I get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise

abdulhasnath
New Member

Hi,

Can someone direct me on what app I need to install to get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise?

I have installed a forwarder and set the deployment/receiver server address to the address of where Splunk Enterprise is installed.
I have followed the Splunk Stream guide, and installed this app. Is this the right way?

Many thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

In addition to pointing the forwarder at Splunk Enterprise, you must also tell Splunk Enterprise to accept data from the forwarder.
Go to Settings->Forwarding and receiving and click "Add new" under Receiving. Enter the port number to listen on (usually 9997) and click Save.

---
If this reply helps you, Karma would be appreciated.
0 Karma

abdulhasnath
New Member

Thanks for your answer. I have installed the forwarder + Splunk Enterprise on a server we have. How do I configure it to receive information from my NetFlow appliance, or is it just the case of me sending this information to the IP address + port number of the server that forwarder sits on from my appliance? If so, how do I then view this information on Splunk Enterprise? Sorry for all the questions, this is something new to us.

0 Karma

abdulhasnath
New Member

Also is it possible to add a 'pcap' file and view it in Splunk through dashboards? I've uploaded it via Settings>Data input but cannot see anything, I have also installed Splunk for PCAP files but no success?

0 Karma
Get Updates on the Splunk Community!

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...