Skip to main content
Version: 2.12.1

Splunk Integration

NetFlow Logic provides a suite of Splunk integrations built on a common data foundation — TA-netflow and NetFlow Optimizer (NFO). Together they deliver CIM-compliant, enriched network telemetry to Splunk Enterprise and Splunk Cloud, powering traffic analysis, device health monitoring, and security threat detection across on-premises and multi-cloud environments.


Components​

ComponentTypeRequired By
TA-netflowTechnology Add-onAll integrations except Splunk O11y
NetFlow and SNMP Analytics AppVisualization App—
DDoS Detector AppVisualization App—
ITSI Content PackContent Pack—
Splunk Enterprise SecurityES Integration—
Splunk Observability CloudSeparate Product—
note

TA-netflow is the shared data foundation for the Analytics App, DDoS Detector, ITSI Content Pack, and Splunk Enterprise Security integrations. It must be installed on all relevant Splunk tiers before any of these products can function. Splunk Observability Cloud (O11y) uses a different integration path and does not require TA-netflow.


Guides​


Looking for dashboard documentation for an older app version?

The dashboard reference for the previous NetFlow and SNMP Analytics App is available in the 2.12.0 documentation.