The scenarios outlined below are presented as deployment guidelines for you to consider taking into account your current infrastructure and Splunk deployment. Although you could configure your NetFlow and AWS VPC Flow logs collection exactly as presented in one of the scenarios, these configurations are flexible and can be adjusted to match your needs and hardware resources.
Install NFO/EDFN in your data center
Configure NFO/EDFN VPC Flow logs access with at least one AWS account
Configure NFO output to send data to Splunk Enterprise
Or
Install NFO/EDFN in your data center
Install another EDFN instance in AWS
Configure NFO/EDFN VPC Flow logs access with AWS accounts or AWS roles
Configure NFO output to send data to Splunk Enterprise
Install NFO/EDFN in your data center
Configure NFO/EDFN VPC Flow logs access with at least one AWS account
Configure NFO output to send data to Splunk Forwarder, and Splunk Forwarder to send data to Splunk Cloud
Or
Install NFO/EDFN in your data center
Install another EDFN instance in AWS
Configure NFO/EDFN VPC Flow logs access with AWS accounts or AWS roles
Configure NFO output to send data to Splunk Forwarder, and Splunk Forwarder to send data to Splunk Cloud
Install NFO/EDFN and Splunk Forwarder in your AWS environment
Configure NFO/EDFN VPC Flow logs access with AWS accounts or AWS roles
Configure NFO output to send data to Splunk Forwarder, and Splunk Forwarder to send data to Splunk Cloud
Install NFO/EDFN and Splunk Forwarder in your AWS environment
Configure NFO/EDFN VPC Flow logs access with AWS accounts or AWS roles
Configure NFO output to send data to Splunk Forwarder, and Splunk Forwarder to send data to Splunk Enterprise