All Apps and Add-ons

NetFlow for Splunk not working after upgrading to 3.0.2

sgardne
Explorer

I have searched around the splunkbase quite a bit and have not yet found a solution. We were previously using the nfdump solution. We upgraded to the NetFlow Integrator 3.0.2 and now we don't get any data. The Integrator is configured to listen on port 9995. There is definitely traffic coming in on 9995, the UDP input for 9995 is configured, but I do not get any results when searching for "sourcetype=netflow". I've also tried removing the directory from /opt/splunk/etc/apps/ and reinstalling the app after that. Any assistance would be greatly appreciated.

0 Karma
1 Solution

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

View solution in original post

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

sgardne
Explorer

Thanks for the call yesterday. If I get some spare time, I may set up a test server with the standard edition.

0 Karma

NetFlow_Logic
Contributor

Hello sgardne, I am sorry to hear that you are having some issues and I would be happy to assist you. The app creates a default data input as follows;

UDP Port: 11514
source type: netflow

It appears you have everything configured correctly, would you be available for a secure remote session via WebEx so we can take a look? Please contact us at: support@netflowlogic.com and include your company contact info and we can schedule a session.

Thank You!

0 Karma

sgardne
Explorer

I left the default one in the inputs list and created a new UDP input and manually set its type to "netflow". I will come to your site and see about doing a remote session. Thanks.

0 Karma

sgardne
Explorer

Also it would appear the server is not even listening on port 9995.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...