All Apps and Add-ons

Netflow for Splunk- no data shown in Splunk

itatcapital
Explorer

Hello,

I have just instaled Splunk v6 oon Windows 2008 Server
I have installed the Netflow for Splunk App on the same server
I have installed the netflow Integrator on the same windows server.
I have configured one router to send its Netflow v9 data to the Netflow Integrator.

The Netflow Integrator product receives data.
It is configured to send to Splunk.
No data is seen in Splunk.
I have set up a data input for Splunk.

According to the Splunk Home page, Data is being indexed.

set up:
router netflow v9 --> netflow integrator 10.10.10.1:9995 --> splunk 10.10.0.1:10514

data input set up:

UDP port 10514, source = flowintegrator

When I look at teh netflow for Splunk App dashboard, no data is being displayed.

i am obviously missing something.

any help is appreciated.

IT@C

0 Karma

itatcapital
Explorer

Hi,
thanks for the replies. It was the weekend here so could not reply earlier.

@martin_mueller:
I have installed SOS and it needs 1.7 of sideview_utils not 1.3.5, which is on the splunk apps site.
I am trying to get the latest version installed and talking to splunk now (having issues but will get there...)

sideviewutils version = 3.2
launching sos reports error, splunk encountered the following unknown module" "SideviewUtils". The view may not load properly.

@dmaislin_splunk:
thanks. I had a look but no results when searching.
I am obviously missing something...

cheers,
itatc

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Examine the searches in the app and dashboards to make sure that they are referencing your data. What happens if you just type a search like:

source=flowintegrator

0 Karma

itatcapital
Explorer

Hi,

thanks for the reply.

I had a look but no results when searching.
I am obviously missing something...

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You mentioned data being indexed, but you're not seeing it anywhere - chances are it's ending up in indexes not expected by the dashboard you're looking at.

Grab a copy of the SoS app from http://apps.splunk.com/app/748/ and look at the indexing dashboards. They'll tell you if there's data coming in split by hosts, indexes, sourcetypes - you'll see at a glance if you're getting data or not even if you're still unfamiliar with Splunk itself. It's also great for future debugging.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The minimum SideviewUtils version required by SoS is 1.1.7, not 1.7 - getting 3.x with the free internal use license doesn't hurt though.

0 Karma

itatcapital
Explorer

hi,

thanks for the reply.

I have installed SOS and it needs 1.7 of sideview_utils not 1.3.5, which is on the splunk apps site.

I am trying to get the latest version installed and talking to splunk now (having issues but will get there...)

sideviewutils version = 3.2

launching sos reports error, splunk encountered the following unknown module" "SideviewUtils". The view may not load properly.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...