07-18-2017 10:27 AM
All ,
I'm looking to see if it's possible to leverage flow information collected by a stealthwatch sensor in another application.
Based on my research , the stealthwatch sensor will provide flow information including application layer information like URL, etc.
I'm trying to avoid having to place yet another span collector into the environment.
Is it possible to glean this information from Stealthwatch?
If so, what format would it be in?
-Scott
Solved! Go to Solution.
07-18-2017 11:20 AM
The Stealthwatch Flow Sensor exports data in IPFIX format (see RFCs 7011, 7012). Any system that can consume IPFIX (or NetFlow or any of the compatible formats) should be able to consume it. Some of the datapoints encoded in the Flow Sensor's data are recorded in "enterprise fields". Those fields which are publicly labeled will use IANA standard IP Flow Information Export (IPFIX) Entities.
07-18-2017 11:11 AM
Scott,
The current version (6.9) of Stealthwatch Flow Sensor exports data in IPFIX format.
I hope this helps.
Brian
07-18-2017 11:13 AM
Thanks for the reply Brian.
Is there a sample export or documentation that details the included information?
-Scott
07-18-2017 11:20 AM
The Stealthwatch Flow Sensor exports data in IPFIX format (see RFCs 7011, 7012). Any system that can consume IPFIX (or NetFlow or any of the compatible formats) should be able to consume it. Some of the datapoints encoded in the Flow Sensor's data are recorded in "enterprise fields". Those fields which are publicly labeled will use IANA standard IP Flow Information Export (IPFIX) Entities.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide