Splunk Enterprise

Splunk IPFIX from NSX-T

Hamidreza74
Explorer

Hello Everyone

I have a problem with receiving IPFIX flow From NSX-T 3.1.

this is a summary of what I do:

I checked Firewall things and it doesn't have any problem because I can see IPFIX flow with Wireshark on the Splunk server.

I use Splunk_TA_stream and splunk_app_stream 8.0.1 and I can Get IPFix flow with IPFIX Generator( flowalyzer).

I change the Splunk Stream configuration for those IPFIX fields that NSX-T sends. because some of IPFIX is not Standard.

 

I changed the Splunk Stream configuration based on these Link according to this Link:

https://emc.extremenetworks.com/content/oneview/docs/analytics/docs/pur_splunk.htm?Highlight=Splunk

https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.0/nsxt_30_admin.pdf

Does anybody have experience in Receiving IPFIX flow from NSX-T?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...