All Apps and Add-ons

Netflow for Splunk- no data shown in Splunk

itatcapital
Explorer

Hello,

I have just instaled Splunk v6 oon Windows 2008 Server
I have installed the Netflow for Splunk App on the same server
I have installed the netflow Integrator on the same windows server.
I have configured one router to send its Netflow v9 data to the Netflow Integrator.

The Netflow Integrator product receives data.
It is configured to send to Splunk.
No data is seen in Splunk.
I have set up a data input for Splunk.

According to the Splunk Home page, Data is being indexed.

set up:
router netflow v9 --> netflow integrator 10.10.10.1:9995 --> splunk 10.10.0.1:10514

data input set up:

UDP port 10514, source = flowintegrator

When I look at teh netflow for Splunk App dashboard, no data is being displayed.

i am obviously missing something.

any help is appreciated.

IT@C

0 Karma

itatcapital
Explorer

Hi,
thanks for the replies. It was the weekend here so could not reply earlier.

@martin_mueller:
I have installed SOS and it needs 1.7 of sideview_utils not 1.3.5, which is on the splunk apps site.
I am trying to get the latest version installed and talking to splunk now (having issues but will get there...)

sideviewutils version = 3.2
launching sos reports error, splunk encountered the following unknown module" "SideviewUtils". The view may not load properly.

@dmaislin_splunk:
thanks. I had a look but no results when searching.
I am obviously missing something...

cheers,
itatc

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Examine the searches in the app and dashboards to make sure that they are referencing your data. What happens if you just type a search like:

source=flowintegrator

0 Karma

itatcapital
Explorer

Hi,

thanks for the reply.

I had a look but no results when searching.
I am obviously missing something...

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You mentioned data being indexed, but you're not seeing it anywhere - chances are it's ending up in indexes not expected by the dashboard you're looking at.

Grab a copy of the SoS app from http://apps.splunk.com/app/748/ and look at the indexing dashboards. They'll tell you if there's data coming in split by hosts, indexes, sourcetypes - you'll see at a glance if you're getting data or not even if you're still unfamiliar with Splunk itself. It's also great for future debugging.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The minimum SideviewUtils version required by SoS is 1.1.7, not 1.7 - getting 3.x with the free internal use license doesn't hurt though.

0 Karma

itatcapital
Explorer

hi,

thanks for the reply.

I have installed SOS and it needs 1.7 of sideview_utils not 1.3.5, which is on the splunk apps site.

I am trying to get the latest version installed and talking to splunk now (having issues but will get there...)

sideviewutils version = 3.2

launching sos reports error, splunk encountered the following unknown module" "SideviewUtils". The view may not load properly.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...