Hello,
I want to see the inflows and outflows of a switch.
I need your advice, please.
But I think that with the switch, we don't need a forwarder
My problem is exactly in the creation of dashbord.
configure an forwarder to forward log file data of your switch on your indexer splunk using an universal forwarder .
to do it, see this link http://answers.splunk.com/answers/50082/how-do-i-configure-a-splunk-forwarder-on-linux.html
after you can write searchs or do dashboard to visualization inflow and outflow of a switch
sorry for my english.