Hello team,.
I've the following topology:
PC with Cisco Anyconnect configured with NVM ------ Collector ------ Splunk Enterprise with NVM addon
Now, everything is working fine from Wiresahrk perspective, I'm receiving flows on collector, and collector send it to Splunk enterprise.
Issue is, that on splunk, I can't see anything on dashboards, why?
One more thing: the captured data on Splunk server appears with SRC IP of the VPN client, and DST IP is the collector..why?
And, why i can't capture traffic destined to 20519 and 20520 on Splunk server? I capture only the traffic as mentioned above destined to port 2055
... View more