User's Guide

Table Of Contents
Part 3 Configuring each Analytics Engine to Export IPFIX Data to the Splunk
200 of 218
3. Use the following steps for each engine you want exporting flows to
Splunk,
a. Click on its Configuration page.
b. Expand the IPFIX/Netflow Exporter section and fill out the required fields.
c. Ensure that Export Enabled is checked.
d. Set the Export IP to the Splunk server IP address.
e. Set the Export Port to 2055 unless this has been customized in Splunk.
f. Set the Protocol to either IPFIX or IPFIX with Padded Strings.
g. Select Save.
The Metadata contains some protocol-specific data for the analysis of DNS,
HTTP, etc. This additional data can double the size of the records.
4. Enforce the changes by expanding Engines in the left-panel of Analytics >
Configuration, selecting the engine in the left-panel menu, and clicking the
Enforce button. The Splunk Search displays "netflowdata" within a minute
or two.