Integration Netflow with Splunk
Kernel Settings
nano /etc/sysctl.conf# Increase kernel buffer sizes for reliable packet capture
net.core.rmem_default = 33554432
net.core.rmem_max = 33554432
net.core.netdev_max_backlog = 10000/sbin/sysctl -pPrerequisites
Monitor netflow file through universal forwarder
Cronjob for Netflow
Last updated