All Apps and Add-ons

Splunk Add-on for Netflow Windows compatibility

jmcrabb
Explorer

Are there plans to make a Windows Server compatible version of this add-on? If so, what's the timeframe?

Jim

0 Karma
1 Solution

rgaleone1
Path Finder

Jim -
This TA relies on NFDUMP tools to capture, and translate NetFlow off the wire, from binary data into flat files for indexing into Splunk. NFDUMP tools are only available for *nix systems at this time and I don't see them being ported to Windows anytime soon. This is out of the control of Splunk, but I would point you to NetFlow for Splunk powered by NetFlow Integrator. NetFlow Integrator is compatible with Windows, although I've never used it on a Windows box. A link to NFDUMP tools should you consider spinning up a *nix box.

Hope this helps.

[Edit]: Additional answers to similar questions.

View solution in original post

rgaleone1
Path Finder

Jim -
This TA relies on NFDUMP tools to capture, and translate NetFlow off the wire, from binary data into flat files for indexing into Splunk. NFDUMP tools are only available for *nix systems at this time and I don't see them being ported to Windows anytime soon. This is out of the control of Splunk, but I would point you to NetFlow for Splunk powered by NetFlow Integrator. NetFlow Integrator is compatible with Windows, although I've never used it on a Windows box. A link to NFDUMP tools should you consider spinning up a *nix box.

Hope this helps.

[Edit]: Additional answers to similar questions.

jmcrabb
Explorer

Thanks for the info!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...