All Apps and Add-ons

NetFlow for Splunk not working after upgrading to 3.0.2

sgardne
Explorer

I have searched around the splunkbase quite a bit and have not yet found a solution. We were previously using the nfdump solution. We upgraded to the NetFlow Integrator 3.0.2 and now we don't get any data. The Integrator is configured to listen on port 9995. There is definitely traffic coming in on 9995, the UDP input for 9995 is configured, but I do not get any results when searching for "sourcetype=netflow". I've also tried removing the directory from /opt/splunk/etc/apps/ and reinstalling the app after that. Any assistance would be greatly appreciated.

0 Karma
1 Solution

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

View solution in original post

NetFlow_Logic
Contributor

Thank you for taking the time to work with us today. As we discovered you are sending NetFlow v9 and NetFlow for Splunk currently supports NetFlow v5. Our Standard Edition supports v5, v9, jFlow, and NSEL.

sgardne
Explorer

Thanks for the call yesterday. If I get some spare time, I may set up a test server with the standard edition.

0 Karma

NetFlow_Logic
Contributor

Hello sgardne, I am sorry to hear that you are having some issues and I would be happy to assist you. The app creates a default data input as follows;

UDP Port: 11514
source type: netflow

It appears you have everything configured correctly, would you be available for a secure remote session via WebEx so we can take a look? Please contact us at: support@netflowlogic.com and include your company contact info and we can schedule a session.

Thank You!

0 Karma

sgardne
Explorer

I left the default one in the inputs list and created a new UDP input and manually set its type to "netflow". I will come to your site and see about doing a remote session. Thanks.

0 Karma

sgardne
Explorer

Also it would appear the server is not even listening on port 9995.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...