Skip to content

j105rob/ipfix

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

26 Commits
 
 
 
 
 
 

Repository files navigation

Splunk Add-on for IPFIX

This Technology Add-on (TA) allows Splunk to ingest IPFIX flow data over UDP, implementing an IPFIX collector with support for enterprise specific information elements defined in iespec or xml files by private enterprise numbers.

The extracted data will be ingested by Splunk as ASCII text data, with fields, template id, and flow sequence information.

This TA can be run on a Splunk Forwarder and can listen for and parse Netflow v9+, Appflow and other IPFIX streams sent over UDP. It is cross-platform and works on Windows, Linux, and OSX. It can be configured to run from splunkd and stream data directly to Splunk, or to run as a linux daemon streaming data to disk (which can be monitored by Splunk).

About

Splunk TA for IPFIX

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 100.0%