Installation
Pre-installation Steps
NetFlow and SNMP Analytics for Splunk App relies on *flow data processed by NetFlow Optimizer™ (NFO) and enables you to analyze it using Splunk® Enterprise or Splunk® Cloud.
To download a free trial of NetFlow Optimizer, please visit https://www.netflowlogic.com/download/ and register to receive the FREE trial license. Please see NetFlow Optimizer Installation and NetFlow Optimizer Administration Guide and follow instructions for your platform.
NetFlow data is sent to Splunk from NFO in syslog or JSON formats.
Whether you use Splunk Enterprise or Splunk Cloud, configure your Splunk Data inputs accordingly per your accepted best practices.
You need to install both NetFlow and SNMP Analytics for Splunk App and Technology Add-On for NetFlow:
- NetFlow and SNMP Analytics for Splunk App (netflow) (https://splunkbase.splunk.com/app/489/)
- Technology Add-On for NetFlow (TA-netflow) (https://splunkbase.splunk.com/app/1838/)
NFO can send data to Splunk using one of the following options:
- Directly on UDP input port of Splunk Indexer (OK for POC, but not recommended in production due to potential loss of data)
- Via Splunk HEC
- Via Splunk Forwarder
- Via rsyslog / syslog-ng and Splunk forwarders
- Via Splunk Connect for Syslog
Installing into a Splunk Cloud Deployment
You must be a Splunk Cloud administrator to install and manage apps in your Splunk Cloud deployment. The procedure for installing apps and add-ons for use with your Splunk Cloud instance depends on the type of your Splunk Cloud deployment and the version of Splunk Cloud that you are running. Please visit Splunk Cloud Platform Admin Manual for details: https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/SelfServiceAppInstall.
Installing Splunk App and TA
Install the App on your Splunk Search Heads
NetFlow and SNMP Analytics for Splunk App (netflow) is available here: (https://splunkbase.splunk.com/app/489/).
Several dashboards of the App rely on Force Directed App for Splunk for Topology View. Please make sure it is installed in your Splunk environment: https://splunkbase.splunk.com/app/3767/ to use Topology View.
This App requires the Technology Add-On for NetFlow (TA-netflow).