The TA-Savvius-nix and TA-Savvius-win technlogy add-on's configure a Splunk Forwarder to send data from an Omnipliance (Linux) or an OmniPeek Capture Engine (Windows) to a Splunk Server running the Savvius for Splunk dashboards. The technology add-on's tell the Splunk Forwarder where to find the CSV files generated by the Capture Engine, and what to do with them.
The Savvius For Splunk App can be found here:
https://splunkbase.splunk.com/app/2730
The technology add-on's can be found here:
TA-Savvius-nix - https://splunkbase.splunk.com/app/2746/
TA-Savvius-win - https://splunkbase.splunk.com/app/2747/
Version 1.0 of the TA-Savvius-nix is compatible with:
Version 1.0 of the TA-Savvius-win is compatible with:
The Savvius for Splunk Network Dashboards are supported by Savvius for customers who have purshased maintenance with their Savvius products.
Savvius for Splunk supports the following server platforms in the versions supported by Splunk Enterprise:
Important: These instructions are for the TA only. To view the data, download the Savvius for Splunk Network Dashboards for the Splunk Server at https://splunkbase.splunk.com/app/2730
The reason for the capture name of “Splunk” is because the inputs.conf file in the TA tells the Splunk forwarder which capture to collect CSV files for. If the capture is named something different, then change the name of the folder in the inputs.conf file to match the capture name. “…” can be used in place of the capture name to collect CSV report files from all captures.
In order for an Omnipliance or an OmniPeek Capture Engine to generate analysis that can be saved to CSV files and ingested into Splunk, certain Analysis Options have to be enabled. Which Analysis Options are enabled depends on what types of analysis will be useful to you. It is important to understand that the more analysis enabled, the lower the performance is going to be. Performance in this case is how much traffic can be captured.
When creating your Splunk captures, be sure and go to the Analysis Options Tab in the Capture Options Dialog. Here is where the analysis options are configured. By default, everything will be enabled. With everything enabled, the analysis performance, or maximum data rate that can be captured and processed, although dependent on many factors like packet size, number of nodes, protocols, etc.., will be less than 1Gbps. By selectivly disabling analysis that is not important to you, performance will increase siginificantly.
Performance can also be increased by using a smart tap to load balance the traffic over multiple captures on different ports, as well as multiple Omnipliances and OmniPeek Capture Engines.
In order to generate CSV files that Splunk can index, Analysis Options have to be enabled for the Splunk capture. Each type of CSV file has a list of fields as the first row of the file. The Savvius for Splunk Dashboards uses a seperate sourcetype for each of the different types of CSV files that are imported from the Splunk Forwarder into the Splunk Server. Some of the files share the same data-model and use the same sourcetype. The name of each sourcetype is listed below along with the file of files that it is associated with:
New Release
Important Note: This release is incompatible with all previous releases. But it's worth it. We have removed the creation and use of indexes by the app, and are using sourcetype instead.
- Changed default time to last 1 hour.
Change Savvius logo icon to red V
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.