NetFlow Optimizer Integration: The NetFlow and SNMP Analytics for Splunk App works in tandem with NetFlow Optimizer (NFO) software, a powerful system that processes flow data (NetFlow, sFlow, IPFIX, etc.) and cloud flow logs before feeding them into Splunk for analysis. This is illustrated in the following diagram.
• Supported Flow Formats: NetFlow v5, v9, sFlow, IPFIX, JFlow, AppFlow, etc.
• Supported Cloud Platforms: AWS VPC Flow Logs, Google Cloud VPC Flow Logs, Microsoft Azure NSG Flow Logs
• Supported SNMP Versions: v2c, v3
NFO enriches flow data with valuable context to enhance your analysis. This includes:
• DNS Names: Identify applications and services utilizing the network.
• VM Names: Gain insights into traffic originating from specific virtual machines.
• Cloud Virtual Network Names: Understand traffic flow within your cloud environment.
• GeoIP: Identify geographic locations of communicating devices.
• IP Reputation: Flag potential security threats based on IP reputation databases.
• Applications: Identify applications generating network traffic.
• User Identity: Correlate network activity with specific users (if available).
NetFlow and SNMP Analytics for Splunk App: Install this App on search heads within your Splunk environment.
Technology Add-on for NetFlow (TA-netflow): This add-on is a prerequisite and needs to be installed on search heads, indexers, and forwarders. You can download TA-netflow from https://splunkbase.splunk.com/app/1838/.
For more details, visit https://docs.netflowlogic.com/integrations-and-apps/integrations-with-splunk/netflow-analytics-splunk-app/installation
For more details, visit https://docs.netflowlogic.com/integrations-and-apps/integrations-with-splunk/netflow-analytics-splunk-app/administration
Added several new dashboards:
- Traffic Using Critical Ports
- Communications with Malicious Hosts
- Added tstats (TS) dashboards
- Network Conversations by Duration TS
- Network Conversations by Country TS
- Network Conversations by Autonomous Systems TS
- Additional filters added to TCP Health dashboard
- Bugfixes
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.