Splunk Netflow dashboard using Network Topology visualization and Network Toolkit addons
>> YOUR LINK HERE: ___ http://youtube.com/watch?v=vLGjjeqyTtg
Dashboard that helps me understand activity in my home lab looking at netflow data from my OPNsense firewall. This dashboard starts with a simple timechart that gives me a trend of average mb_in across all of my devices. I have OPNsense configured to send netflow data v9 to a Splunk independent stream forward which then sends to my Splunk indexer. • This dashboard utilizes the Network Topology - Custom Visualization and the Network Toolkit to be more interactive and perform WHOIS actions on source IP addresses. You will need to have both of those apps installed for the dashboard to work as intended. • You will also need to adjust the base search of this dashboard to match the index where the netflow data lives. This dashboard uses post processing and you will need to edit the source XML provided. • Network Topology - Custom Visualization: • https://splunkbase.splunk.com/app/3762/ • Network Toolkit: • https://splunkbase.splunk.com/app/3491/ • Splunk Stream documentation: • https://docs.splunk.com/Documentation... • GoSplunk: • https://gosplunk.com/ • https://gosplunk.com/author/thall • OPNsense Netflow Configuration: • https://docs.opnsense.org/manual/netf... • travis.
#############################
