Monitoring Splunk

How can I monitor T1 all activity to determine periodic slowdown?

nola50
New Member

I have an account that I am headed to 11/09/2011 that the Internet is slowing down at different times of the day. I'd like to monitor the traffic of the site and see what could be the issue. There is no server installed, just about 10 users doing data entry and accessing the Internet.

How can I setup Splunk to monitor and see what's causing the slow down?

Tags (2)
0 Karma

nola50
New Member

It's a Cisco 1721 and looks like it supports Netflow. I'll have to see what it takes to get the app to load and run.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Obviously, you would need some kind of data source that describes the flow of traffic through the Internet connection. For most folks, this would mean getting data out of the edge router.

One data source is SNMP counters. You can script up snmpget to log data about ifInOctets and ifOutOctets on the router, and then Splunk that. This will tell you if there is a bandwidth issue, but not necessarily what is causing it.

Another data source is Netflow. There is an app for that which enables Splunk to load/process Netflow data. However, not all routers have the ability to export Netflow data.

Your mileage may vary in using either of these to resolve your client's issue. This isn't an incredibly straightforward problem to resolve either with Splunk or without.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...