I am setting up netflow ticket collection on splunk.
I am a very occasional user, and I come to you ask help.
What interests me are specific dialogs of my network infrastructure :
src=net_A to dest=net_B or src=net_B to dest=net_A
All the rest i don't want splunk to keep it and store it, for example net_B to net_B, net_B to net_C, .....
I think I must use CIRDMATCH for my need, to do the filtering I think it must be done on the forwarder but not sure
Is there any possibility of doing this ?
My splunk infrastructure:
splunk 8.1.1 2 Forwarder
2 Search Head
1 server deployment / license