Getting Data In

netflow data captured but not being displayed

dodes
New Member

I'm running on Ubuntu 12.04.1.

This issue I am struggling with is that netflow is not displaying the data captured. The nfdump.log file is in the location /opt/splunk/etc/apps/netflow/log/nfdump and a cat of the file indicates that the flows are being recorded properly yet when I go to the dashboard no matter what criteria i use it indicates 'no results found'.

Any thoughts on where to look?

Thanks.

Tags (1)
0 Karma

jonathanmorcom
Explorer

the app appears to be missing the index location in inputs.conf.

add this to each stanzer and it will work.

vim /opt/splunk/etc/apps/netflow/default/inputs.conf

add index=netflow_si_traffic to the 3 stanzer in the file and restart splunk.

0 Karma

jonathanmorcom
Explorer

I'm having same issue on Debian...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...