I'm running on Ubuntu 12.04.1.
This issue I am struggling with is that netflow is not displaying the data captured. The nfdump.log file is in the location /opt/splunk/etc/apps/netflow/log/nfdump and a cat of the file indicates that the flows are being recorded properly yet when I go to the dashboard no matter what criteria i use it indicates 'no results found'.
Any thoughts on where to look?
Thanks.
the app appears to be missing the index location in inputs.conf.
add this to each stanzer and it will work.
vim /opt/splunk/etc/apps/netflow/default/inputs.conf
add index=netflow_si_traffic to the 3 stanzer in the file and restart splunk.
I'm having same issue on Debian...