Getting Data In

netflow data captured but not being displayed

dodes
New Member

I'm running on Ubuntu 12.04.1.

This issue I am struggling with is that netflow is not displaying the data captured. The nfdump.log file is in the location /opt/splunk/etc/apps/netflow/log/nfdump and a cat of the file indicates that the flows are being recorded properly yet when I go to the dashboard no matter what criteria i use it indicates 'no results found'.

Any thoughts on where to look?

Thanks.

Tags (1)
0 Karma

jonathanmorcom
Explorer

the app appears to be missing the index location in inputs.conf.

add this to each stanzer and it will work.

vim /opt/splunk/etc/apps/netflow/default/inputs.conf

add index=netflow_si_traffic to the 3 stanzer in the file and restart splunk.

0 Karma

jonathanmorcom
Explorer

I'm having same issue on Debian...

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...