Installation Overview
Installation Steps in AWS
- Install NetFlow Optimizer AWS AMI in one of your AWS accounts
- Configure NFO output for Splunk or other syslog/JSON receiving system (IP address and port number where NFO sends out syslogs)
- Configure VPC Flow Logs
- Configure NFO AWS VPC Flow Logs Modules and corresponding EDFN Agent
- Install NetFlow Analytics for Splunk App and TA-netflow Add-on
- In Splunk select NetFlow Analytics for Splunk App and go to Cloud > Amazon AWS > AWS Traffic Overview
Installation Steps in Azure
- Install NetFlow Optimizer in one of your Azure accounts
- Configure NFO output for Splunk or other syslog/JSON receiving system (IP address and port number where NFO sends out syslogs)
- Configure NSG Flow Logs
- Configure NFO Azure NSG Flow Logs Modules and corresponding EDFN Agent
- Install NetFlow Analytics for Splunk App and TA-netflow Add-on
- In Splunk select NetFlow Analytics for Splunk App and go to Cloud > Microsoft Azure > Azure Traffic Overview
Installation Steps in GCP
- Install NetFlow Optimizer in one of your GCP accounts
- Configure NFO output for Splunk or other syslog/JSON receiving system (IP address and port number where NFO sends out syslogs)
- Configure VPC Flow Logs
- Configure NFO GCP VPC Flow Logs Modules and corresponding EDFN Agent
- Install NetFlow Analytics for Splunk App and TA-netflow Add-on
- In Splunk select NetFlow Analytics for Splunk App and go to Cloud > Google Cloud > GCP Traffic Overview
Installation Steps on Premises
- Install NetFlow Optimizer – Linux or Windows in your data center
- Install EDFN in one of your AWS / Azure / Google Cloud accounts and configure EDFN to NFO communications (one line config parameter) or configure EDFN installed with NFO in your data center to access your AWS / Azure / Google Cloud account
- Configure NFO output for Splunk (IP address and port number where NFO sends out syslogs)
- Configure VPC (NSG) Flow Logs
- Configure NFO AWS / Azure / GCP Flow Logs Modules and corresponding EDFN Agent
- Install NetFlow Analytics for Splunk App and TA-netflow Add-on
- In Splunk, select NetFlow Analytics for Splunk App and go to Cloud > Amazon AWS (or Microsoft Azure or Google Cloud)