Getting Data In

Splunk IPFIX from NSX-T

Hamidreza74
Explorer

Hello Everyone

I have a problem with receiving IPFIX flow From NSX-T 3.1.

this is a summary of what I do:

I checked Firewall things and it doesn't have any problem because I can see IPFIX flow with Wireshark on the Splunk server.

I use Splunk_TA_stream and splunk_app_stream 8.0.1 and I can Get IPFix flow with IPFIX Generator( flowalyzer).

I change the Splunk Stream configuration for those IPFIX fields that NSX-T sends. because some of IPFIX is not Standard.

 

I changed the Splunk Stream configuration based on these Link according to this Link:

https://emc.extremenetworks.com/content/oneview/docs/analytics/docs/pur_splunk.htm?Highlight=Splunk

https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/nsxt_30_admin.pdf

Does anybody have experience in Receiving IPFIX flow from NSX-T?

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...