All Apps and Add-ons

NetFlow for Splunk not working after upgrading to 3.0.2

sgardne
Explorer

I have searched around the splunkbase quite a bit and have not yet found a solution. We were previously using the nfdump solution. We upgraded to the NetFlow Integrator 3.0.2 and now we don't get any data. The Integrator is configured to listen on port 9995. There is definitely traffic coming in on 9995, the UDP input for 9995 is configured, but I do not get any results when searching for "sourcetype=netflow". I've also tried removing the directory from /opt/splunk/etc/apps/ and reinstalling the app after that. Any assistance would be greatly appreciated.

0 Karma
1 Solution

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

View solution in original post

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

sgardne
Explorer

Thanks for the call yesterday. If I get some spare time, I may set up a test server with the standard edition.

0 Karma

NetFlow_Logic
Contributor

Hello sgardne, I am sorry to hear that you are having some issues and I would be happy to assist you. The app creates a default data input as follows;

UDP Port: 11514
source type: netflow

It appears you have everything configured correctly, would you be available for a secure remote session via WebEx so we can take a look? Please contact us at: support@netflowlogic.com and include your company contact info and we can schedule a session.

Thank You!

0 Karma

sgardne
Explorer

I left the default one in the inputs list and created a new UDP input and manually set its type to "netflow". I will come to your site and see about doing a remote session. Thanks.

0 Karma

sgardne
Explorer

Also it would appear the server is not even listening on port 9995.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...