Splunk Integration
NetFlow Logic provides a suite of Splunk integrations built on a common data foundation — TA-netflow and NetFlow Optimizer (NFO). Together they deliver CIM-compliant, enriched network telemetry to Splunk Enterprise and Splunk Cloud, powering traffic analysis, device health monitoring, and security threat detection across on-premises and multi-cloud environments.
Components
| Component | Type | Required By |
|---|---|---|
| TA-netflow | Technology Add-on | All integrations except Splunk O11y |
| NetFlow and SNMP Analytics App | Visualization App | — |
| DDoS Detector App | Visualization App | — |
| ITSI Content Pack | Content Pack | — |
| Splunk Enterprise Security | ES Integration | — |
| Splunk Observability Cloud | Separate Product | — |
TA-netflow is the shared data foundation for the Analytics App, DDoS Detector, ITSI Content Pack, and Splunk Enterprise Security integrations. It must be installed on all relevant Splunk tiers before any of these products can function. Splunk Observability Cloud (O11y) uses a different integration path and does not require TA-netflow.
Guides
The dashboard reference for the previous NetFlow and SNMP Analytics App is available in the 2.12.0 documentation.