2015-02-06 01:06 PM
Has anyone started pulling in Netflow data into SA? If so, are you able to see the "direction" meta and run the RSA provided Netflow reports? I am unable to do either properly. I added a custom line in my log concentrator index-concentrator-custom.xml file, and the meta appears in an investigation, but reports come back empty for the same data/time frame.
Here is the info from my index-concentrator-custom.xml file:
<?xml version="1.0" encoding="utf-8"?>
<language level="IndexNone" defaultAction="Auto">
<!--NetFlow rsaFlow Keys-->
<key description="Direction" level="IndexValues" name="direction" valueMax="100000" format="Text" />
</language>
2015-02-08 08:31 PM
Hi Brian
Check out this post by Davide that explains how to add the Direction meta-tagging to your system.
The Direction meta is not created by the NetFlow parser itself, but by App rules that match ip.src and ip.dst against a list of network ranges that you can customise to match your company's IP address scheme.
2015-02-08 08:31 PM
Hi Brian
Check out this post by Davide that explains how to add the Direction meta-tagging to your system.
The Direction meta is not created by the NetFlow parser itself, but by App rules that match ip.src and ip.dst against a list of network ranges that you can customise to match your company's IP address scheme.
2015-02-09 10:54 AM
That is exactly what I was looking for! Thank you.