Skip to main content
Version: Next

Integration with Splunk Enterprise Security

To integrate NetFlow Optimizer with Splunk Enterprise Security all you need is to install Technology Add-on for NetFlow (https://splunkbase.splunk.com/app/1838/).

When you use NFO to preprocess and enrich flow data, you sources and destinations will have not only IP addresses, but also contextual information, such as DNS names, VM names, etc.

You can also use this enriched data in Splunk ES Traffic search and other dashboards.