User's Guide

Table Of Contents
Overview
194 of 218
Stream Flow Data from
ExtremeAnalytics into Splunk
ExtremeAnalytics includes the ability to stream flow data from an Analytics
engine to Splunk. To help you use Splunk with ExtremeAnalytics, we added a
Splunk directory to the Extreme Management Center
NetSight/appdata/Purview directory.
The Splunk directory contains the following:
l A PDF with instructions describing how to add Extreme’s enterprise IPFIX fields into
the Splunk vocabulary and adjust the Splunk streaming app to process the Extreme
IPFIX format.
l Files that you can copy to the Splunk server to facilitate integration, instead of
manually editing the files.
Use the procedures in this section to send Splunk-enriched network flow data
using IPFIX.
Environment
l Extreme Management Center 8.2 and later
l Splunk 7.2.6 (single server deployment) and later
l Splunk Stream 7.1.3 and later
Overview
You can configure the Splunk Stream app to process Netflow/IPFIX flow records
and add the data into the Splunk data store. Configure this partly by editing text
files on the file system, and partly by using the web UI.
The instance of Splunk Stream at any site may already be configured to import
one or more flow sources. Because of this, you must take care to merge the
needed changes for ExtremeAnalytics with the existing file contents. After you
make the file system changes, restart Splunk. Then, define a new stream” using
the user interface. Finally, enable and deploy the IPFIX exporter of
ExtremeAnalytics from the Extreme Management Center user interface.