Hi there,
We are just looking at using Netflow for our Cisco ASA's rather than using syslog (networks request). However, we are experiencing issues with the "NetFlow for Splunk powered by NetFlow Integrator" App... We can see traffic for UDP/9995 being received by the hosting server. However we are not seeing any data in Splunk.
There are no errors in any of the app log files, or in Splunk log files
This is a standard installation of the app (i.e. standard install/config, accepted license) on a single server.
Is there any points that we can look into?
Thanks in advance.
The differences are as follows;
NetFlow for Splunk App
Ideal for less than 100 flow records per second
NetFlow for Splunk Essential App
Ideal for more than 100 flow records per second
NetFlowIntegrator Standard
Splunk Apps
Let me know if that helps clarify the differences
The differences are as follows;
NetFlow for Splunk App
Ideal for less than 100 flow records per second
NetFlow for Splunk Essential App
Ideal for more than 100 flow records per second
NetFlowIntegrator Standard
Splunk Apps
Let me know if that helps clarify the differences
That's great thanks.
The NetFlow for Splunk app does not support Cisco ASA NSEL, however, you can use our Standard Edition software available on our web site as a 30-Day free trial at: www.netflowlogic.com along with our most recent Splunk App - Cisco ASA Monitor available on Splunkbase at: http://splunk-base.splunk.com/apps/72686/cisco-asa-monitor-for-netflow-standard
You can install our software in minutes, begin converting NSEL into Syslog, and utilize the Cisco ASA Monitor App to gain immediate insights such as;
Top Bandwidth Consumers
Top Destinations
Top Violators
Top Connectors
Let us know if you have any questions, or require any assistance with configuration by contacting support at: https://netflowlogic.zendesk.com/home
@dmiller2010, What is the difference with the integrator versions then?