Getting Data In

netflow data captured but not being displayed

dodes
New Member

I'm running on Ubuntu 12.04.1.

This issue I am struggling with is that netflow is not displaying the data captured. The nfdump.log file is in the location /opt/splunk/etc/apps/netflow/log/nfdump and a cat of the file indicates that the flows are being recorded properly yet when I go to the dashboard no matter what criteria i use it indicates 'no results found'.

Any thoughts on where to look?

Thanks.

Tags (1)
0 Karma

jonathanmorcom
Explorer

the app appears to be missing the index location in inputs.conf.

add this to each stanzer and it will work.

vim /opt/splunk/etc/apps/netflow/default/inputs.conf

add index=netflow_si_traffic to the 3 stanzer in the file and restart splunk.

0 Karma

jonathanmorcom
Explorer

I'm having same issue on Debian...

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...