Getting Data In

How can I get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise

abdulhasnath
New Member

Hi,

Can someone direct me on what app I need to install to get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise?

I have installed a forwarder and set the deployment/receiver server address to the address of where Splunk Enterprise is installed.
I have followed the Splunk Stream guide, and installed this app. Is this the right way?

Many thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

In addition to pointing the forwarder at Splunk Enterprise, you must also tell Splunk Enterprise to accept data from the forwarder.
Go to Settings->Forwarding and receiving and click "Add new" under Receiving. Enter the port number to listen on (usually 9997) and click Save.

---
If this reply helps you, Karma would be appreciated.
0 Karma

abdulhasnath
New Member

Thanks for your answer. I have installed the forwarder + Splunk Enterprise on a server we have. How do I configure it to receive information from my NetFlow appliance, or is it just the case of me sending this information to the IP address + port number of the server that forwarder sits on from my appliance? If so, how do I then view this information on Splunk Enterprise? Sorry for all the questions, this is something new to us.

0 Karma

abdulhasnath
New Member

Also is it possible to add a 'pcap' file and view it in Splunk through dashboards? I've uploaded it via Settings>Data input but cannot see anything, I have also installed Splunk for PCAP files but no success?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...