icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading NetFlow and SNMP Analytics for Splunk
SHA256 checksum (netflow-and-snmp-analytics-for-splunk_4549.tgz) 99e1f657f516efb9f26751c0285aa7a363fc37a82071292c582d5027b1acb0e3 SHA256 checksum (netflow-and-snmp-analytics-for-splunk_4537.tgz) e2035b5cad5b8856678cea1176b4b13e551587f929646f3423a0f2dc1d9a4897 SHA256 checksum (netflow-and-snmp-analytics-for-splunk_4527.tgz) 91d35c81a9ded2ae8885a8dd39e848169bf1565815f7594107df8f8e17e48883 SHA256 checksum (netflow-and-snmp-analytics-for-splunk_4522.tgz) 4c3baaebf5d58f6f176472e40ba465b2ba8d7e4a3dc24ff6ae958fdc95876f34 SHA256 checksum (netflow-and-snmp-analytics-for-splunk_4516.tgz) bca10db5591ca43512bf9285e5b35ad505668921a4155ef7e2fa9ca9c4e5ec2d SHA256 checksum (netflow-and-snmp-analytics-for-splunk_4512.tgz) e9c5e975b0f196d6fda46505bc8a9785e41653644c6254e6514db627d2f57cd7
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

NetFlow and SNMP Analytics for Splunk

Splunk Cloud
Overview
Details
Unleash Network Insights with NetFlow and SNMP Analytics for Splunk!

NetFlowLogic and Splunk deliver a powerful network traffic analysis solution. This collaboration empowers network and security analysts with real-time insights into your network infrastructure, both on-premises and across cloud platforms like AWS, Microsoft Azure, Oracle Cloud Infrastructure, and Google Cloud Platform.

The NetFlow and SNMP Analytics for Splunk App seamlessly integrates NetFlow Optimizer (NFO) with Splunk's industry-leading investigation and visualization capabilities. NFO processes various flow formats (NetFlow, sFlow, IPFIX) and cloud flow logs, transforming them into insightful, actionable data for Splunk. This empowers you to:

• Gain Comprehensive Visibility: Monitor network traffic across your entire infrastructure, including cloud deployments and on-premises networks.
• Simplify Security Analysis: Correlate application and user activity for faster and more accurate security investigations.
• Optimize Network Performance: Identify bottlenecks, optimize resource allocation, and proactively address potential congestion issues.
• Automate Workflows: Streamline network monitoring tasks and free up valuable IT resources for strategic initiatives.

Key Features:

• Supports industry-standard flow formats (NetFlow v5, v9, sFlow, IPFIX) and cloud flow logs (AWS, Azure, OCI, GCP).
• Provides real-time and historical network traffic analysis.
• Leverages SNMP polling and traps (v2c and v3) for comprehensive device health monitoring.
• Enriches flow data with context (DNS names, VM names, GeoIP, IP reputation, applications, user identity).
• Identifies overloaded network interfaces and potential security threats.
• Offers cost-effective deployment across your entire network infrastructure.

Download the NetFlow and SNMP Analytics for Splunk App and experience the power of unified network traffic analysis.

Overview

NetFlow Optimizer Integration: The NetFlow and SNMP Analytics for Splunk App works in tandem with NetFlow Optimizer (NFO) software, a powerful system that processes flow data (NetFlow, sFlow, IPFIX, etc.) and cloud flow logs before feeding them into Splunk for analysis. This is illustrated in the following diagram.

Technical Specifications

• Supported Flow Formats: NetFlow v5, v9, sFlow, IPFIX, JFlow, AppFlow, etc.
• Supported Cloud Platforms: AWS VPC Flow Logs, Google Cloud VPC Flow Logs, Microsoft Azure NSG Flow Logs
• Supported SNMP Versions: v2c, v3

Data Enrichment

NFO enriches flow data with valuable context to enhance your analysis. This includes:
• DNS Names: Identify applications and services utilizing the network.
• VM Names: Gain insights into traffic originating from specific virtual machines.
• Cloud Virtual Network Names: Understand traffic flow within your cloud environment.
• GeoIP: Identify geographic locations of communicating devices.
• IP Reputation: Flag potential security threats based on IP reputation databases.
• Applications: Identify applications generating network traffic.
• User Identity: Correlate network activity with specific users (if available).

Installation

NetFlow and SNMP Analytics for Splunk App: Install this App on search heads within your Splunk environment.
Technology Add-on for NetFlow (TA-netflow): This add-on is a prerequisite and needs to be installed on search heads, indexers, and forwarders. You can download TA-netflow from https://splunkbase.splunk.com/app/1838/.

For more details, visit https://docs.netflowlogic.com/integrations-and-apps/integrations-with-splunk/netflow-analytics-splunk-app/installation

Configuration

For more details, visit https://docs.netflowlogic.com/integrations-and-apps/integrations-with-splunk/netflow-analytics-splunk-app/administration

Release Notes

Version 4.5.49
Sept. 16, 2024
  • New dashboard: Network Conversations Top (firewall policy) Violators
  • Improved dashboard: Network Topology with Insights
Version 4.5.37
Aug. 15, 2024
  • New dashboard: Network Conversations with NetScaler RTT and Retransmissions
  • New dashboard: Network Topology with Insights
  • Minor bug fixes
Version 4.5.27
June 18, 2024
  • added parameter: to process lookup on the federated search head set local=true
  • added destination port in Application fields
Version 4.5.22
Feb. 21, 2024
  • Added new dashboard: "SNMP Devices CPU and Memory"
  • Improved "Interface Errors and Discards" dashboard
  • Updated Azure dashboards
  • Bugfixes
Version 4.5.16
March 22, 2023
  • added support for IPv6 networks
  • bugfix in "Interface Errors and Discards" dashboard
  • fixed savedsearch updating the interfaces_20003 lookup table
Version 4.5.12
Dec. 21, 2022

Added several new dashboards:
- Traffic Using Critical Ports
- Communications with Malicious Hosts
- Added tstats (TS) dashboards
- Network Conversations by Duration TS
- Network Conversations by Country TS
- Network Conversations by Autonomous Systems TS
- Additional filters added to TCP Health dashboard
- Bugfixes


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.